resource "nomad_job" "lego" { jobspec = file("${path.module}/lego.nomad") } resource "nomad_acl_policy" "secrets_certs_write" { name = "secrets-certs-write" description = "Write certs to secrets store" rules_hcl = <