blob: c33762c444c77cdd3195981b5f77d34095589a45 [file] [log] [blame]
Giorgi Lekveishviliec6b3cc2023-12-01 16:30:04 +04001{{- if and .Values.deployment.enabled .Values.rbac.create }}
2apiVersion: rbac.authorization.k8s.io/v1
3kind: ClusterRole
4metadata:
5 name: {{ template "coredns.fullname" . }}
6 labels: {{- include "coredns.labels" . | nindent 4 }}
7rules:
8- apiGroups:
9 - ""
10 resources:
11 - endpoints
12 - services
13 - pods
14 - namespaces
15 verbs:
16 - list
17 - watch
18- apiGroups:
19 - discovery.k8s.io
20 resources:
21 - endpointslices
22 verbs:
23 - list
24 - watch
25{{- if .Values.rbac.pspEnable }}
26- apiGroups:
27 - policy
28 - extensions
29 resources:
30 - podsecuritypolicies
31 verbs:
32 - use
33 resourceNames:
34 - {{ template "coredns.fullname" . }}
35{{- end }}
36{{- end }}