# Allow access to configure pki/au/syd1 secret backend --- rules: - path: "pki/au/syd1/config/*" capabilities: - create - update - delete - read - list auth: approle: - tf_vault