Repository navigation
Expand file tree
/
Copy pathtoolpass.yaml
More file actions
163 lines (146 loc) · 7.54 KB
/
Copy pathtoolpass.yaml
File metadata and controls
163 lines (146 loc) · 7.54 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
# toolpass configuration. One flat list of connections.
#
# An integration is the product (kubernetes, jira). A connection is one
# configured system of that product. Callers name the connection by id.
#
# Secrets are never written here. Every credential is a reference:
# env:NAME read from the environment
# file:/path read from a file on every use (rotating tokens keep working)
#
# Every connection also accepts ca_file, tls_server_name, proxy_url and timeout.
# `toolpass catalog <integration>` lists the keys and actions of an integration;
# docs/integrations/<integration>.md explains the credential to create.
api_key: env:TOOLPASS_API_KEY
# listen: ":8080"
# decision_log: /var/log/toolpass/decisions.log # or stderr (default), stdout, none
# decision_cache_seconds: 30 # allow/deny answers reused this long; 0 disables
# identity_cache_seconds: 900 # email -> account lookups reused this long
connections:
# Smoke-test connection. Talks to nothing. Remove it once real connections work.
- id: demo
integration: fake
users: dana@example.com
admins: admin@example.com
# - id: k8s-prod-eu
# integration: kubernetes
# url: https://10.20.0.5:6443
# ca_file: /etc/toolpass/ca/prod-eu.pem
# tls_server_name: kubernetes
# credential: file:/secrets/k8s-prod-eu-token # ServiceAccount token, see test/kind/toolpass-rbac.yaml
# username_template: "oidc:{email}"
# group_prefix: "oidc:"
# - id: argocd-prod
# integration: argocd
# kubernetes_connection: k8s-prod-eu
# namespace: argocd
# user_subject: none # or email, when the IdP subject is the email
# - id: gitlab-main
# integration: gitlab
# url: https://gitlab.example.com
# credential: env:GITLAB_TOKEN # read_api token of an administrator
# identity_mode: admin_search
# - id: github-acme
# integration: github
# organization: acme
# app_id: Iv1.abcdef0123456789
# credential: file:/secrets/github-app.pem # GitHub App private key
# identity_mode: saml
# - id: snowflake-prod
# integration: snowflake
# account: myorg-myaccount
# user: TOOLPASS
# role: SECURITYADMIN # or a custom role with MANAGE GRANTS
# credential: file:/secrets/snowflake-toolpass.p8 # the user's RSA private key (key-pair auth)
# - id: vault-prod
# integration: vault
# url: https://vault.example.com:8200
# alias_mount: oidc/ # the auth method whose aliases are the users' emails
# credential: env:VAULT_TOKEN # or auth_mode: approle with role_id and the secret_id as credential
# # token_policies: developers # policies the oidc role attaches at login
# # namespace: admin/
# - id: azure-corp
# integration: azure
# tenant_id: 11111111-2222-3333-4444-555555555555
# client_id: 66666666-7777-8888-9999-000000000000
# credential: env:AZURE_CLIENT_SECRET # app registration with Reader at the root management group
# # microsoft365_connection: m365-corp # resolve users through the microsoft365 connection instead of Graph
# - id: linear-acme
# integration: linear
# credential: env:LINEAR_API_KEY # personal API key of a workspace admin, or an OAuth token with auth_mode: oauth
# - id: zendesk-acme
# integration: zendesk
# url: https://acme.zendesk.com
# username: toolpass-bot@acme.com # the administrator the API token acts as
# credential: env:ZENDESK_API_TOKEN
# # auth_mode: oauth # credential is then an OAuth access token
# - id: datadog-acme
# integration: datadog
# api_key: env:DATADOG_API_KEY
# credential: env:DATADOG_APP_KEY # application key scoped to user_access_read, teams_read, *_read
# # url: https://api.datadoghq.eu # EU site
# - id: pagerduty-acme
# integration: pagerduty
# credential: env:PAGERDUTY_API_KEY # read-only General Access REST API key
# # url: https://api.eu.pagerduty.com # EU service region
# - id: bitbucket-acme
# integration: bitbucket
# workspace: acme # Cloud: the workspace slug
# credential: env:BITBUCKET_TOKEN # workspace access token (read repository, project, account scopes)
# - id: bitbucket-dc
# integration: bitbucket
# edition: datacenter
# url: https://bitbucket.acme.internal
# credential: env:BITBUCKET_DC_TOKEN # HTTP access token of an administrator
# - id: jira-main
# integration: jira
# url: https://acme.atlassian.net
# username: toolpass-bot@acme.com
# credential: env:JIRA_TOKEN
# - id: confluence-main
# integration: confluence
# url: https://acme.atlassian.net
# username: toolpass-bot@acme.com
# credential: env:JIRA_TOKEN
# identity_connection: jira-main # Confluence cannot look users up by email itself
# - id: slack-acme
# integration: slack
# credential: env:SLACK_BOT_TOKEN # xoxb- token of an internal app with read scopes
# - id: aws-prod
# integration: aws
# account_id: "123456789012"
# region: eu-west-1
# role_arn: arn:aws:iam::123456789012:role/toolpass-read # iam:SimulatePrincipalPolicy, iam:ListRoles
# credential: env:TOOLPASS_AWS_CRED # the literal ambient:auto, or JSON {access_key_id, secret_access_key}
# identity_mode: identity_center
# identity_center_role_arn: arn:aws:iam::210987654321:role/toolpass-identity-center-read
# identity_center_region: eu-west-1
# identity_store_id: d-936712345a
# sso_instance_arn: arn:aws:sso:::instance/ssoins-1234567890abcdef
# implicit_deny_as: deny
# - id: m365-contoso
# integration: microsoft365
# tenant_id: contoso.onmicrosoft.com
# client_id: 00000000-0000-0000-0000-000000000000
# credential: file:/secrets/m365-app.key # PEM private key, with certificate_file; or the client secret
# certificate_file: /etc/toolpass/m365-app.crt
# - id: google-acme
# integration: googleworkspace
# credential: file:/secrets/google-sa.json # service-account key with domain-wide delegation
# admin_email: toolpass-admin@acme.com # custom admin role: Users > Read, Groups > Read
# - id: databricks-prod
# integration: databricks
# url: https://adb-1234567890123456.7.azuredatabricks.net
# client_id: a1b2c3d4-e5f6-7890-abcd-ef1234567890 # service principal application id
# credential: env:DATABRICKS_OAUTH_SECRET # its OAuth secret; or auth_mode: token with a PAT
# - id: gcp-acme
# integration: googlecloud
# scope: organization:123456789012 # where the service account has roles/iam.securityReviewer
# credential: file:/secrets/gcp-toolpass.json # service-account key; or auth_mode: keyless on GCE/GKE
# googleworkspace_connection: google-acme # optional: user_not_found and suspended accounts
# - id: salesforce-prod # UNVERIFIED integration, see docs/integrations/salesforce.md
# integration: salesforce
# url: https://acme.my.salesforce.com
# client_id: 3MVG9... # consumer key of the External Client App
# credential: file:/secrets/salesforce.key # PEM private key of the app certificate
# username: toolpass@acme.com
# api_version: v66.0