--- apiVersion: secrets.hashicorp.com/v1beta1 kind: VaultAuth metadata: name: default namespace: cephrgw-system spec: method: kubernetes mount: k8s/au/syd1 vaultConnectionRef: vso-system/default allowedNamespaces: - cephrgw-system kubernetes: # Shared "default" role: binds the namespace's default ServiceAccount and # grants the templated kv/kubernetes/namespace///* read policy, so # no per-app terraform-vault change is needed. role: default serviceAccount: default audiences: - vault tokenExpirationSeconds: 600