blob: 9b57f1356e36b3fb7bb766a074d6649619064d25 [file] [log] [blame]
giof6ad2982024-08-23 17:42:49 +04001apiVersion: rbac.authorization.k8s.io/v1
2kind: Role
3metadata:
4 name: {{ .Values.serviceAccountName }}-access-secrets
5 namespace: {{ .Release.Namespace }}
6rules:
7- apiGroups: [""]
8 resources: ["secrets"]
9 verbs: ["get", "watch", "list", "patch", "update", "create"]
10---
11apiVersion: rbac.authorization.k8s.io/v1
12kind: RoleBinding
13metadata:
14 name: {{ .Values.serviceAccountName }}-access-secrets
15 namespace: {{ .Release.Namespace }}
16subjects:
17- kind: ServiceAccount
18 name: {{ .Values.serviceAccountName }}
19 namespace: {{ .Release.Namespace }}
20roleRef:
21 kind: Role
22 name: {{ .Values.serviceAccountName }}-access-secrets
23 apiGroup: rbac.authorization.k8s.io