"no":kubectl auth can-i get configmap/extension-apiserver-authentication -n kube-system --as="system:serviceaccount:svc-secret-store-domain-c##:api-aggregator"vSphere Kubernetes Service
This issue occurs in Secret Store Service because the package does not automatically create the necessary RoleBinding for the api-aggregator service account to access the required extension-apiserver-authentication.
This issue has been resolved in the latest releases of the Secret Store Service (9.0.2.0 and above). To remediate this failure, upgrade the Secret Store Service to a compatible version as per Supervisor version. Refer Broadcom Interoperability Matrix
Secret Store Service Download: Broadcom Support Portal