Another update of rbac.yaml

This commit is contained in:
Chris Stuurman 2024-03-27 22:27:49 +02:00
parent fd6cec29d0
commit 57463faa25
2 changed files with 40 additions and 1 deletions

View File

@ -129,3 +129,42 @@ subjects:
kind: ServiceAccount kind: ServiceAccount
name: {{ .Values.certManager.serviceAccountName }} name: {{ .Values.certManager.serviceAccountName }}
namespace: {{ .Values.certManager.namespace }} namespace: {{ .Values.certManager.namespace }}
---
# Grant cert-manager permission to read secrets from cert-manager ns (i.e. to read the api key for sthome)
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: {{ include "sthome-webhook.fullname" . }}:sthome-auth
namespace: {{ .Values.certManager.namespace }}
labels:
app: {{ include "sthome-webhook.name" . }}
chart: {{ include "sthome-webhook.chart" . }}
release: {{ .Release.Name }}
heritage: {{ .Release.Service }}
rules:
- apiGroups:
- ''
resources:
- 'secrets'
verbs:
- 'get'
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: {{ include "sthome-webhook.fullname" . }}:sthome-auth
namespace: {{ .Values.certManager.namespace }}
labels:
app: {{ include "sthome-webhook.name" . }}
chart: {{ include "sthome-webhook.chart" . }}
release: {{ .Release.Name }}
heritage: {{ .Release.Service }}
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: {{ include "sthome-webhook.fullname" . }}:sthome-auth
subjects:
- apiGroup: ""
kind: ServiceAccount
name: {{ include "sthome-webhook.fullname" . }}
namespace: {{ .Values.certManager.namespace }}

View File

@ -12,7 +12,7 @@ labels: sthome-webhook
certManager: certManager:
namespace: ix-cert-manager namespace: ix-cert-manager
serviceAccountName: cert-manager-certmanager serviceAccountName: cert-manager-certmanager-webhook
#secrets: #secrets:
# apiID: # apiID: