Skip to content

HVD: Vault - Standardize: Sentinel policy-as-code - #3081

Draft
danbr-ibm wants to merge 1 commit into
mainfrom
migrate-hvd-pr-394-sentinel
Draft

HVD: Vault - Standardize: Sentinel policy-as-code#3081
danbr-ibm wants to merge 1 commit into
mainfrom
migrate-hvd-pr-394-sentinel

Conversation

@danbr-ibm

@danbr-ibm danbr-ibm commented Aug 11, 2026

Copy link
Copy Markdown
Collaborator

Summary

New section covering Sentinel in the Vault Operating Guide for Standardization. Provides platform teams with prescriptive guidance for adopting Vault Enterprise's policy-as-code layer, including policy model, enforcement configuration, four reusable standardization patterns, and operational caveats.

Source PR being migrated: https://github.com/hashicorp/hvd-docs/pull/394

Changes

New file: content/validated-designs/docs/docs/vault/administration-guide/sentinel-policy-management.mdx
Action: Create new page in the Vault Administration Guide and wire it into the validated designs nav and redirects.

Main guidance themes:

  • Policy model comparison: ACL vs RGP vs EGP with evaluation order and when-to-use table
  • Enforcement levels (advisory / soft-mandatory / hard-mandatory) and soft-mandatory override mechanics
  • Safe configuration: sentinel stanza options and http import SSRF/latency warning
  • Four standardization patterns with code examples: MFA enforcement on login paths, identity group guardrails, time-bounded token validity, delegated EGP management
  • Operational caveats: performance overhead, namespace/RGP inheritance version boundaries, root token bypass, and policy lifecycle considerations

Supporting migration updates:

  • content/validated-designs/data/docs-nav-data.json - adds the new Vault administration guide page to nav
  • content/validated-designs/redirects.jsonc - adds redirect from the old HVD standardization Sentinel path

Notes

This is a draft PR created as part of the HVD migration from hashicorp/hvd-docs into hashicorp/web-unified-docs. The content is being moved as-is in draft form so any follow-up review and cleanup can happen in the correct repository.

Migrate the Sentinel draft content from the old hvd-docs PR into web-unified-docs so the HVD 2.0 work can continue in the repository that now owns validated design content.

This adds the new Vault administration guide page, exposes it in the validated designs navigation, and preserves the legacy HVD URL through redirects so the old path continues to resolve after the move.

The content is being carried over as a draft-equivalent migration rather than cleaned up during transfer. Any follow-up review or content adjustments can now happen in the web-unified-docs PR instead of the retired hvd-docs flow.
@github-actions

github-actions Bot commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

Vercel Previews Deployed

Name Status Preview Updated (UTC)
Dev Portal ✅ Ready (Inspect) Visit Preview Tue Aug 11 15:14:48 UTC 2026
Unified Docs API ✅ Ready (Inspect) Visit Preview Tue Aug 11 15:09:48 UTC 2026

@danbr-ibm danbr-ibm added AI used Warning: human SME checks required Validated Designs labels Aug 11, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Broken Link Checker

This PR contains broken links, but won't be blocked. Use this report to improve content quality:

Quick Actions

  • Internal links (HashiCorp sites): Please fix these - they impact user experience
  • External links: Consider if these are essential or can be updated/removed
  • Temporary issues: External sites may recover - check again before merging

Need Help?


Internal Links

Full Github Actions output

External Links

Summary

Status Count
🔍 Total 3
✅ Successful 0
⏳ Timeouts 0
🔀 Redirected 0
👻 Excluded 3
❓ Unknown 0
🚫 Errors 0
⛔ Unsupported 0

Full Github Actions output

@danbr-ibm
danbr-ibm requested a review from HashiJin August 12, 2026 08:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

AI used Warning: human SME checks required Validated Designs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant