--- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: cert-manager-vault-token-creator labels: app.kubernetes.io/name: "cert-manager-config" app.kubernetes.io/instance: "cert-manager-config" rules: - apiGroups: [""] resources: ["serviceaccounts/token"] verbs: ["create"]