{{- if and .Values.create.enabled (eq .Values.create.appRole.mode "k8s") -}} apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: name: {{ include "vault.fullname" . }}-role rules: - apiGroups: [""] resources: ["secrets"] verbs: ["create", "patch", "get"] {{- end -}}