# Allow access to read pki_root issuers --- rules: - path: "pki_root/issuer/*" capabilities: - read - list auth: approle: - tf_vault