keycloak-vault-(cloud|client): add specific role for managing k8s secrets
Because composite roles are no longer mapped to zone realm the vault policies for caascad-devops were never used.
The change introduce new caascad-vault-k8s-secrets customer roles (global and per cluster) that are added to caascad-devops composite roles.
Theses new roles will be mapped to the zone realm.
The vault policies to manage k8s secrets mapped to these new roles.