blob: 9b57f1356e36b3fb7bb766a074d6649619064d25 [file] [log] [blame]
Giorgi Lekveishviliefc43ea2024-09-09 19:11:41 +04001apiVersion: rbac.authorization.k8s.io/v1
2kind: Role
3metadata:
Giorgi Lekveishvilib451c2f2024-09-11 19:03:52 +04004 name: {{ .Values.serviceAccountName }}-access-secrets
Giorgi Lekveishviliefc43ea2024-09-09 19:11:41 +04005 namespace: {{ .Release.Namespace }}
6rules:
7- apiGroups: [""]
8 resources: ["secrets"]
Giorgi Lekveishvili1c9e61e2024-09-11 13:25:34 +04009 verbs: ["get", "watch", "list", "patch", "update", "create"]
Giorgi Lekveishviliefc43ea2024-09-09 19:11:41 +040010---
11apiVersion: rbac.authorization.k8s.io/v1
12kind: RoleBinding
13metadata:
Giorgi Lekveishvilib451c2f2024-09-11 19:03:52 +040014 name: {{ .Values.serviceAccountName }}-access-secrets
Giorgi Lekveishviliefc43ea2024-09-09 19:11:41 +040015 namespace: {{ .Release.Namespace }}
16subjects:
17- kind: ServiceAccount
18 name: {{ .Values.serviceAccountName }}
19 namespace: {{ .Release.Namespace }}
20roleRef:
21 kind: Role
Giorgi Lekveishvilib451c2f2024-09-11 19:03:52 +040022 name: {{ .Values.serviceAccountName }}-access-secrets
Giorgi Lekveishviliefc43ea2024-09-09 19:11:41 +040023 apiGroup: rbac.authorization.k8s.io