Skip to content

Commit 106de76

Browse files
authored
Add a Firefly clusterrole and clusterrolebinding to the venafi-kubernetes-agent chart (#616)
Signed-off-by: Richard Wall <richard.wall@venafi.com>
1 parent 1f00f09 commit 106de76

File tree

1 file changed

+27
-0
lines changed
  • deploy/charts/venafi-kubernetes-agent/templates

1 file changed

+27
-0
lines changed

deploy/charts/venafi-kubernetes-agent/templates/rbac.yaml

Lines changed: 27 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -288,3 +288,30 @@ subjects:
288288
- kind: ServiceAccount
289289
name: {{ include "venafi-kubernetes-agent.serviceAccountName" . }}
290290
namespace: {{ .Release.Namespace }}
291+
---
292+
apiVersion: rbac.authorization.k8s.io/v1
293+
kind: ClusterRole
294+
metadata:
295+
name: {{ include "venafi-kubernetes-agent.fullname" . }}-firefly-reader
296+
labels:
297+
{{- include "venafi-kubernetes-agent.labels" . | nindent 4 }}
298+
rules:
299+
- apiGroups: ["firefly.venafi.com"]
300+
resources:
301+
- issuers
302+
verbs: ["get", "list", "watch"]
303+
---
304+
apiVersion: rbac.authorization.k8s.io/v1
305+
kind: ClusterRoleBinding
306+
metadata:
307+
name: {{ include "venafi-kubernetes-agent.fullname" . }}-firefly-reader
308+
labels:
309+
{{- include "venafi-kubernetes-agent.labels" . | nindent 4 }}
310+
roleRef:
311+
kind: ClusterRole
312+
name: {{ include "venafi-kubernetes-agent.fullname" . }}-firefly-reader
313+
apiGroup: rbac.authorization.k8s.io
314+
subjects:
315+
- kind: ServiceAccount
316+
name: {{ include "venafi-kubernetes-agent.serviceAccountName" . }}
317+
namespace: {{ .Release.Namespace }}

0 commit comments

Comments
 (0)