blob: 88cf40594668e872bf4ac8ec5ba5bb06e82633f4 [file] [log] [blame]
giolekva01a6b792021-11-11 19:01:17 +04001apiVersion: rbac.authorization.k8s.io/v1
2kind: ClusterRole
3metadata:
giolekva30850462021-12-01 16:23:50 +04004 name: {{ .Release.Namespace }}-cert-manager-gandi-webhook-secret-reader # TODO(giolekva): make namespace part configurable
giolekva01a6b792021-11-11 19:01:17 +04005 namespace: {{ .Release.Namespace }}
6rules:
7- apiGroups:
8 - ""
9 resources:
10 - secrets
11 verbs:
12 - get
13---
14apiVersion: rbac.authorization.k8s.io/v1
15kind: ClusterRoleBinding
16metadata:
giolekva30850462021-12-01 16:23:50 +040017 name: {{ .Release.Namespace }}-cert-manager-gandi-webhook-secret-reader
giolekva01a6b792021-11-11 19:01:17 +040018 namespace: {{ .Release.Namespace }}
19roleRef:
20 apiGroup: rbac.authorization.k8s.io
21 kind: ClusterRole
giolekva30850462021-12-01 16:23:50 +040022 name: {{ .Release.Namespace }}-cert-manager-gandi-webhook-secret-reader
giolekva01a6b792021-11-11 19:01:17 +040023subjects:
24- kind: ServiceAccount
25 name: {{ .Values.certManager.gandiWebhookSecretReader }}
26 namespace: {{ .Values.certManager.namespace }}