---
title: Charmhub | Deploy Vault using Charmhub - The Open Operator Collection
description: Deploy the latest version of Vault as a Kubernetes Operator on any cloud.
url: https://charmhub.io/vault-k8s/docs/h-vault-charm-policies
---

# Vault

[Canonical Telco](https://charmhub.io/publisher/telco-charmers "View all packages from Canonical Telco")

* [Canonical Telco](https://charmhub.io/publisher/telco-charmers "View all packages from Canonical Telco")

Platform:

2.0/stable 565

```
juju deploy vault-k8s --channel 2.0/stable
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

---

#### Relevant links

* [Homepage](https://charmhub.io/vault-k8s)

---

#### Contacts

##### Maintainers

+ [Matrix Channel](https://matrix.to/#/!yAkGlrYcBFYzYRvOlQ:ubuntu.com?via=ubuntu.com&via=matrix.org&via=mozilla.org)

* [Submit a bug](https://github.com/canonical/vault-k8s-operator/issues)

---

Share your thoughts on this charm with the community on discourse.

[Join the discussion](https://discourse.charmhub.io/)

# Charm Policies

When running the [authorize-charm](https://charmhub.io/vault-k8s/actions) Juju action, the charm creates a Vault policy to ensure it can only access what it needs for day-to-day operations.

These rules are defined in the [charm\_policy.hcl](https://github.com/canonical/vault-k8s-operator/blob/main/src/templates/charm_policy.hcl) file.

Paths starting with the `charm—` prefix should only be accessed by the charm; it is strongly discouraged for users to create resources under these paths.

---
