# Allow access to read pki/au/syd1 issuers --- rules: - path: "pki/au/syd1/issuer/*" capabilities: - read - list auth: approle: - tf_vault