keycloak-vault-cloud: forward only zone roles to KC cloud
When authenticating on infra realm all realm roles of the user were returned to KC cloud (full scope).
This change disable full scope on KC cloud clients and put only the related zone roles in the scope.