File tree 3 files changed +32
-2
lines changed
3 files changed +32
-2
lines changed Original file line number Diff line number Diff line change @@ -261,8 +261,17 @@ metadata:
261
261
roleRef :
262
262
apiGroup : rbac.authorization.k8s.io
263
263
kind : ClusterRole
264
- name : cluster-admin
264
+ name : {{ .Values.gotk.rbac.adminClusterRole.name }}
265
265
subjects :
266
266
- kind : ServiceAccount
267
267
name : fluxcd
268
268
namespace : " {{ .Release.Namespace }}"
269
+ {{ if .Values.gotk.rbac.adminClusterRole.rules }}
270
+ ---
271
+ apiVersion : rbac.authorization.k8s.io/v1
272
+ kind : ClusterRole
273
+ metadata :
274
+ name : {{ .Values.gotk.rbac.adminClusterRole.name }}
275
+ rules :
276
+ {{ .Values.gotk.rbac.adminClusterRole.rules | toYaml }}
277
+ {{- end }}
Original file line number Diff line number Diff line change @@ -156,9 +156,18 @@ metadata:
156
156
roleRef :
157
157
apiGroup : rbac.authorization.k8s.io
158
158
kind : ClusterRole
159
- name : cluster-admin
159
+ name : {{ .Values.kraan.rbac.adminClusterRole.name }}
160
160
subjects :
161
161
- kind : ServiceAccount
162
162
name : kraan
163
163
namespace : {{.Release.Namespace}}
164
+ {{ if .Values.kraan.rbac.adminClusterRole.rules }}
165
+ ---
166
+ apiVersion : rbac.authorization.k8s.io/v1
167
+ kind : ClusterRole
168
+ metadata :
169
+ name : {{ .Values.kraan.rbac.adminClusterRole.name }}
170
+ rules :
171
+ {{ .Values.kraan.rbac.adminClusterRole.rules | toYaml }}
172
+ {{- end }}
164
173
{{- end }}
Original file line number Diff line number Diff line change @@ -16,6 +16,12 @@ kraan:
16
16
enabled : true
17
17
rbac :
18
18
enabled : true
19
+ adminClusterRole :
20
+ # admin ClusterRole to be used by the controller, default is cluster-admin
21
+ name : " cluster-admin"
22
+ # specify rules to create a ClusterRole
23
+ # https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.31/#policyrule-v1-rbac-authorization-k8s-io
24
+ # rules: []
19
25
netpolicy :
20
26
enabled : true
21
27
kraanController :
@@ -79,6 +85,12 @@ kraan:
79
85
gotk :
80
86
rbac :
81
87
enabled : true
88
+ adminClusterRole :
89
+ # admin ClusterRole to be used by the controller, default is cluster-admin
90
+ name : " cluster-admin"
91
+ # specify rules to create a ClusterRole
92
+ # https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.31/#policyrule-v1-rbac-authorization-k8s-io
93
+ # rules: []
82
94
netpolicy :
83
95
enabled : true
84
96
You can’t perform that action at this time.
0 commit comments