This guide covers key concepts for mastering Vault Policies in the Vault Certified Associate exam.
Vault Policies are the foundation of access control in HashiCorp Vault. This guide covers the key concepts you need for Objective 2 of the Vault Certified Associate exam, including default behaviors, capabilities, protected paths, and advanced customization.
Vault policies are declarative, path-based rules that grant or deny access. All paths default to deny—if no policy explicitly allows an action, it is not permitted.
Path-based rules control access at granular levels.
Two built-in policies exist by default:
Policy
Description
root
Unrestricted access; bound to the root token.
default
Automatically applied to non-root tokens; can be disabled.