37 lines
781 B
HCL
37 lines
781 B
HCL
resource "nomad_job" "traefik" {
|
|
jobspec = file("${path.module}/traefik.nomad")
|
|
}
|
|
|
|
resource "nomad_acl_policy" "treafik_secrets_certs_read" {
|
|
name = "traefik-secrets-certs-read"
|
|
description = "Read certs to secrets store"
|
|
rules_hcl = <<EOH
|
|
namespace "default" {
|
|
variables {
|
|
path "secrets/certs/*" {
|
|
capabilities = ["read"]
|
|
}
|
|
path "secrets/certs" {
|
|
capabilities = ["read"]
|
|
}
|
|
}
|
|
}
|
|
EOH
|
|
job_acl {
|
|
job_id = resource.nomad_job.traefik.id
|
|
}
|
|
}
|
|
|
|
resource "nomad_acl_policy" "traefik_query_jobs" {
|
|
name = "traefik-query-jobs"
|
|
description = "Allow traefik to query jobs"
|
|
rules_hcl = <<EOH
|
|
namespace "default" {
|
|
capabilities = ["list-jobs", "read-job"]
|
|
}
|
|
EOH
|
|
job_acl {
|
|
job_id = resource.nomad_job.traefik.id
|
|
}
|
|
}
|