Files
buun-stack/jupyterhub/user_policy.hcl
2025-09-03 10:55:16 +09:00

30 lines
686 B
HCL

# User-specific policy for {username}
path "secret/data/jupyter/users/{username}/*" {
capabilities = ["create", "update", "read", "delete", "list"]
}
path "secret/metadata/jupyter/users/{username}/*" {
capabilities = ["list", "read", "delete", "update"]
}
path "secret/metadata/jupyter/users/{username}" {
capabilities = ["list"]
}
# Read access to shared resources
path "secret/data/jupyter/shared/*" {
capabilities = ["read", "list"]
}
path "secret/metadata/jupyter/shared" {
capabilities = ["list"]
}
# Token management capabilities
path "auth/token/lookup-self" {
capabilities = ["read"]
}
path "auth/token/renew-self" {
capabilities = ["update"]
}