| Giorgi Lekveishvili | ec6b3cc | 2023-12-01 16:30:04 +0400 | [diff] [blame] | 1 | {{- if and .Values.deployment.enabled .Values.rbac.create }} |
| 2 | apiVersion: rbac.authorization.k8s.io/v1 |
| 3 | kind: ClusterRole |
| 4 | metadata: |
| 5 | name: {{ template "coredns.fullname" . }} |
| 6 | labels: {{- include "coredns.labels" . | nindent 4 }} |
| 7 | rules: |
| 8 | - apiGroups: |
| 9 | - "" |
| 10 | resources: |
| 11 | - endpoints |
| 12 | - services |
| 13 | - pods |
| 14 | - namespaces |
| 15 | verbs: |
| 16 | - list |
| 17 | - watch |
| 18 | - apiGroups: |
| 19 | - discovery.k8s.io |
| 20 | resources: |
| 21 | - endpointslices |
| 22 | verbs: |
| 23 | - list |
| 24 | - watch |
| 25 | {{- if .Values.rbac.pspEnable }} |
| 26 | - apiGroups: |
| 27 | - policy |
| 28 | - extensions |
| 29 | resources: |
| 30 | - podsecuritypolicies |
| 31 | verbs: |
| 32 | - use |
| 33 | resourceNames: |
| 34 | - {{ template "coredns.fullname" . }} |
| 35 | {{- end }} |
| 36 | {{- end }} |