| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101 |
- {{- if .Values.rbac.create -}}
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRole
- metadata:
- name: {{ include "external-secrets.fullname" . }}-controller
- labels:
- {{- include "external-secrets.labels" . | nindent 4 }}
- rules:
- - apiGroups:
- - "external-secrets.io"
- resources:
- - "secretstores"
- - "clustersecretstores"
- - "externalsecrets"
- verbs:
- - "get"
- - "list"
- - "watch"
- - apiGroups:
- - "external-secrets.io"
- resources:
- - "externalsecrets"
- - "externalsecrets/status"
- verbs:
- - "update"
- - "patch"
- - apiGroups:
- - ""
- resources:
- - "secrets"
- verbs:
- - "get"
- - "list"
- - "watch"
- - "create"
- - "update"
- - "delete"
- - apiGroups:
- - ""
- resources:
- - "events"
- verbs:
- - "create"
- - "patch"
- ---
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRoleBinding
- metadata:
- name: {{ include "external-secrets.fullname" . }}-controller
- labels:
- {{- include "external-secrets.labels" . | nindent 4 }}
- roleRef:
- apiGroup: rbac.authorization.k8s.io
- kind: ClusterRole
- name: {{ include "external-secrets.fullname" . }}-controller
- subjects:
- - name: {{ include "external-secrets.serviceAccountName" . }}
- namespace: {{ .Release.Namespace | quote }}
- kind: ServiceAccount
- ---
- apiVersion: rbac.authorization.k8s.io/v1
- kind: Role
- metadata:
- name: {{ include "external-secrets.fullname" . }}-leaderelection
- namespace: {{ .Release.Namespace | quote }}
- labels:
- {{- include "external-secrets.labels" . | nindent 4 }}
- rules:
- - apiGroups:
- - ""
- resources:
- - "configmaps"
- resourceNames:
- - "external-secrets-controller"
- verbs:
- - "get"
- - "update"
- - "patch"
- - apiGroups:
- - ""
- resources:
- - "configmaps"
- verbs:
- - "create"
- ---
- apiVersion: rbac.authorization.k8s.io/v1
- kind: RoleBinding
- metadata:
- name: {{ include "external-secrets.fullname" . }}-leaderelection
- namespace: {{ .Release.Namespace | quote }}
- labels:
- {{- include "external-secrets.labels" . | nindent 4 }}
- roleRef:
- apiGroup: rbac.authorization.k8s.io
- kind: Role
- name: {{ include "external-secrets.fullname" . }}-leaderelection
- subjects:
- - kind: ServiceAccount
- name: {{ include "external-secrets.serviceAccountName" . }}
- namespace: {{ .Release.Namespace | quote }}
- {{- end }}
|