Open san6789 opened 3 years ago
you need to define read capabilities policy if you are not using root token. i.e.
The "readonly" Policy is:
path "sys/internal/ui/mounts/secret/data/cubbyhole" {
capabilities = ["read", "list"]
}
else recheck the vault process. vault service must be running as root
azureuser@vault-1:~$ vault kv get secret/cubbyhole Error making API request.
URL: GET http://40.86.181.8:8200/v1/sys/internal/ui/mounts/secret/cubbyhole Code: 403. Errors: