| gio | f6ad298 | 2024-08-23 17:42:49 +0400 | [diff] [blame] | 1 | apiVersion: rbac.authorization.k8s.io/v1 |
| 2 | kind: Role |
| 3 | metadata: |
| 4 | name: {{ .Values.serviceAccountName }}-access-secrets |
| 5 | namespace: {{ .Release.Namespace }} |
| 6 | rules: |
| 7 | - apiGroups: [""] |
| 8 | resources: ["secrets"] |
| 9 | verbs: ["get", "watch", "list", "patch", "update", "create"] |
| 10 | --- |
| 11 | apiVersion: rbac.authorization.k8s.io/v1 |
| 12 | kind: RoleBinding |
| 13 | metadata: |
| 14 | name: {{ .Values.serviceAccountName }}-access-secrets |
| 15 | namespace: {{ .Release.Namespace }} |
| 16 | subjects: |
| 17 | - kind: ServiceAccount |
| 18 | name: {{ .Values.serviceAccountName }} |
| 19 | namespace: {{ .Release.Namespace }} |
| 20 | roleRef: |
| 21 | kind: Role |
| 22 | name: {{ .Values.serviceAccountName }}-access-secrets |
| 23 | apiGroup: rbac.authorization.k8s.io |