# esc
Also I'm allowing myself to share my notes on how to configure vault to (almost) get vault HCP work with pulumi ESC + pulumi cloud as it may be useful to someone at some point: • authenticate with vault • enable jwt auth method:
vault auth enable jwt
• configure the jwt auth method:
vault write auth/jwt/config \
    oidc_discovery_url="<>" \
    bound_issuer="<>" \
• create a role
vault write auth/jwt/role/example-role-1 role_type=jwt policies=<SCOPED_VAULT_POLICY> ttl=1h user_claim=sub bound_audiences=<NAME_OF_YOUR_PULUMI_CLOUD_ORG_ASSOCIATED_WITH_YOUR_DEPLOYMENT>