# Allow signing server certificates with servers_default role --- rules: - path: "pki_int/sign/servers_default" capabilities: - update auth: k8s/au/syd1: - huntarr-default - cert_manager_issuer