blob: c48ab48babae7fc52ce03be3365a7c5b59de76f0 [file] [log] [blame]
giolekvab64297c2021-12-13 14:36:32 +04001apiVersion: rbac.authorization.k8s.io/v1
2kind: ClusterRole
3metadata:
4 name: {{ .Release.Namespace }}-nebula-api
5 namespace: {{ .Release.Namespace }}
6rules:
7- apiGroups:
8 - "lekva.me"
9 resources:
10 - nebulacas
11 - nebulacas/status
12 - nebulanodes
13 - nebulanodes/status
14 verbs:
15 - list
16 - get
17 - create
18 - update
19 - watch
20- apiGroups:
21 - ""
22 resources:
23 - secrets
24 verbs:
25 - list
26 - get
27 - create
28 - watch
29---
30apiVersion: rbac.authorization.k8s.io/v1
31kind: ClusterRoleBinding
32metadata:
33 name: {{ .Release.Namespace }}-nebula-api
34 namespace: {{ .Release.Namespace }}
35roleRef:
36 apiGroup: rbac.authorization.k8s.io
37 kind: ClusterRole
38 name: {{ .Release.Namespace }}-nebula-api
39subjects:
40- kind: ServiceAccount
41 name: default
42 namespace: {{ .Release.Namespace }}