kubectl create serviceaccount issuer kubectl get secrets ISSUER_SECRET_REF=$(kubectl get serviceaccount issuer -o json | jq -r ".secrets[].name") cat > vault-issuer.yaml <