# Allow everyone to manage things under kv/users/ path "kv/data/user/{{identity.entity.name}}/*" { capabilities = ["create", "update", "read", "delete"] } path "kv/metadata/user/{{identity.entity.name}}/*" { capabilities = ["list"] } path "kv/metadata/user" { capabilities = ["list"] } path "kv/metadata/+" { capabilities = ["list"] } # Users can manage things under kv/server/ too. path "kv/data/server/*" { capabilities = ["create", "update", "read", "delete"] } path "kv/metadata/server/*" { capabilities = ["list"] } # Users can get SSH keys signed. path "ssh-client/sign/user" { capabilities = ["update"] }