- add approle for kubernetes terraform - ensure it can access consul token for state storage - ensure it can generate root token for managing kubernetes