# Allow management of keys (create, update, delete, list, and read) --- rules: - path: "transit/keys/*" capabilities: - create - update - delete - read - list - path: "transit/keys" capabilities: - read - list auth: approle: - tf_vault