# Allow reading Puppet CA Certificate --- rules: - path: "kv/data/service/puppet/certificates/ca" capabilities: - read auth: approle: - terraform_incus