resource "vault_policy" "k8s_default" { name = "k8s-default" policy = templatefile("bao-policies/k8s-default.hcl", { k8s_auth_backend_accessor = vault_auth_backend.kubernetes.accessor, k8s_secrets_path = vault_mount.static_secrets.path, }) }