| apiVersion: rbac.authorization.k8s.io/v1 |
| kind: Role |
| metadata: |
| name: {{ .Values.serviceAccountName }}-access-secrets |
| namespace: {{ .Release.Namespace }} |
| rules: |
| - apiGroups: [""] |
| resources: ["secrets"] |
| verbs: ["get", "watch", "list", "patch", "update", "create"] |
| --- |
| apiVersion: rbac.authorization.k8s.io/v1 |
| kind: RoleBinding |
| metadata: |
| name: {{ .Values.serviceAccountName }}-access-secrets |
| namespace: {{ .Release.Namespace }} |
| subjects: |
| - kind: ServiceAccount |
| name: {{ .Values.serviceAccountName }} |
| namespace: {{ .Release.Namespace }} |
| roleRef: |
| kind: Role |
| name: {{ .Values.serviceAccountName }}-access-secrets |
| apiGroup: rbac.authorization.k8s.io |