blob: b75b9eb6f0f5f34f5370187b90e88a024240f605 [file] [log] [blame]
Giorgi Lekveishvilid1234c12023-06-19 10:37:06 +04001{{- if .Values.cainjector.enabled }}
2{{- if .Values.global.podSecurityPolicy.enabled }}
3kind: ClusterRole
4apiVersion: rbac.authorization.k8s.io/v1
5metadata:
6 name: {{ template "cainjector.fullname" . }}-psp
7 labels:
8 app: {{ include "cainjector.name" . }}
9 app.kubernetes.io/name: {{ include "cainjector.name" . }}
10 app.kubernetes.io/instance: {{ .Release.Name }}
11 app.kubernetes.io/component: "cainjector"
12 {{- include "labels" . | nindent 4 }}
13rules:
14- apiGroups: ['policy']
15 resources: ['podsecuritypolicies']
16 verbs: ['use']
17 resourceNames:
18 - {{ template "cainjector.fullname" . }}
19{{- end }}
20{{- end }}