# Allow creating and management of authentication backends (AppRole, LDAP, etc.) --- rules: - path: "sys/auth/*" capabilities: - create - update - delete - read - list auth: approle: - tf_vault