Skip to content
Snippets Groups Projects

Reduce cluster admin permissions for Helm chart

Merged Sören Henning requested to merge helm-without-clusterroles into master
5 files
+ 123
15
Compare changes
  • Side-by-side
  • Inline
Files
5
{{- if not (index .Values "kube-prometheus-stack" "global" "rbac" "create") -}}
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: {{ template "theodolite.fullname" . }}-kube-prometheus-operator
labels:
app: {{ template "theodolite.fullname" . }}-kube-prometheus-operator
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: {{ template "theodolite.fullname" . }}-kube-prometheus-operator
subjects:
- kind: ServiceAccount
name: {{ template "theodolite.fullname" . }}-kube-prometheus-operator
namespace: {{ .Release.Namespace }}
{{- end }}
Loading