diff --git a/docs/pages/access-controls/guides/role-templates.mdx b/docs/pages/access-controls/guides/role-templates.mdx index 9fb7ff07dfde3..999e6a7fc5d88 100644 --- a/docs/pages/access-controls/guides/role-templates.mdx +++ b/docs/pages/access-controls/guides/role-templates.mdx @@ -332,7 +332,7 @@ spec: # Functions transform variables. database_users: ['{{email.local(external.email)}}'] - database_labels: + db_labels: 'env': '{{regexp.replace(external.access["env"], "^(staging)$", "$1")}}' # Labels can mix template and hard-coded values. @@ -372,7 +372,7 @@ spec: database_users: ['alice'] # The function regexp.replace will transform and filter only matching values. - database_labels: + db_labels: 'env': 'staging' # Node labels have 'env' replaced from a variable and 'region' hard-coded. diff --git a/docs/pages/access-controls/reference.mdx b/docs/pages/access-controls/reference.mdx index 64f70654605e9..37f4c7d649adc 100644 --- a/docs/pages/access-controls/reference.mdx +++ b/docs/pages/access-controls/reference.mdx @@ -140,7 +140,7 @@ Label | `v3` Default | `v4`, `v5` and `v6` Default `node_labels` | `[{"*": "*"}]` if the role has any logins, else `[]` | `[]` `app_labels` | `[{"*": "*"}]` | `[]` `kubernetes_labels` | `[{"*": "*"}]` | `[]` -`database_labels` | `[{"*": "*"}]` | `[]` +`db_labels` | `[{"*": "*"}]` | `[]` Role `v6` introduced a new field `kubernetes_resources` that allows fine-grained control over Kubernetes resources. See [Kubernetes RBAC](../kubernetes-access/manage-access/rbac.mdx) for more details.