blob: e45a7abe235f0ff955cb9e4c0eb677f1a9857c67 [file] [log] [blame]
Giorgi Lekveishvili5b356462023-06-21 14:45:09 +04001apiVersion: rbac.authorization.k8s.io/v1
2kind: ClusterRole
3metadata:
4 name: cert-manager-gandi
5rules:
6- apiGroups:
7 - acme.bwolf.me
8 resources:
9 - gandi
10 verbs:
11 - "*" # TODO(giolekva): limit
12---
13apiVersion: rbac.authorization.k8s.io/v1
14kind: ClusterRoleBinding
15metadata:
16 name: cert-manager-gandi-binding
17roleRef:
18 apiGroup: rbac.authorization.k8s.io
19 kind: ClusterRole
20 name: cert-manager-gandi
21subjects:
22- kind: ServiceAccount
23 name: {{ .Values.certManager.name }}
24 namespace: {{ .Values.certManager.namespace }}