locals { secret_path = "secret/data/${var.environment}/${var.short_hostname}/certificate" policy_name = "${var.environment}-${var.short_hostname}-cert-policy" approle_name = "${var.environment}-${var.short_hostname}-approle" } resource "vault_policy" "cert_access" { name = local.policy_name policy = <