# Allow reading environment vars for postgres/encapi --- rules: - path: "kv/data/service/encapi/postgres-password" capabilities: - read auth: k8s/au/syd1: - encapi