- !policy
  id: workato-app-dev
  body:
    - !group workato-secrets-dev
    - &variables
        - !variable
            id: sql-password-prod
            kind: password
        - !variable
            id: sql-host-prod
            kind: password
    - !permit
        role: !group /workato-app-dev/workato-secrets-dev       # group declared earlier
        privileges: [read, execute]
        resources: *variables
    - !host workato-us-dev-1
    - !layer workato-us-dev
    - !grant
        role: !layer workato-us-dev
        members:
            - !host workato-us-dev-1
    - !grant
        role: !group workato-secrets-dev
        member: !layer workato-us-dev

To which the expected response would be:

{
    "created_roles": {
        "workato:host:workato-app-dev/workato-us-dev-1": {
            "id": "workato:host:workato-app-dev/workato-us-dev-1",
            "api_key": "1q3ye3gxxxx"
        }
    },
    "version": 1
}


Last updated: 7/17/2024, 3:49:18 PM