# Allow full administration of LDAP auth backend --- rules: - path: "auth/ldap/*" capabilities: - create - update - read - delete - list auth: approle: - tf_vault