# Allow access to manage pki_root secret backend roles --- rules: - path: "pki_root/roles/*" capabilities: - create - update - delete - read - list auth: approle: - tf_vault