From ed8dc0d83302f80bcfbb19de0aacb46ec3e5899f Mon Sep 17 00:00:00 2001 From: vardhaman Date: Tue, 20 Dec 2022 08:57:14 +0530 Subject: [PATCH] psp related fixes for alerting-drivers chart --- .../rancher-alerting-drivers/charts/templates/hardened.yaml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/packages/rancher-alerting/rancher-alerting-drivers/charts/templates/hardened.yaml b/packages/rancher-alerting/rancher-alerting-drivers/charts/templates/hardened.yaml index 8b20a2003..5a5bc247f 100644 --- a/packages/rancher-alerting/rancher-alerting-drivers/charts/templates/hardened.yaml +++ b/packages/rancher-alerting/rancher-alerting-drivers/charts/templates/hardened.yaml @@ -52,11 +52,13 @@ rules: - apiGroups: [""] resources: ["serviceaccounts"] verbs: ["get", "patch"] + {{- if .Capabilities.APIVersions.Has "policy/v1beta1/PodSecurityPolicy" }} - apiGroups: ["policy"] resources: ["podsecuritypolicies"] verbs: ["use"] resourceNames: - {{ include "drivers.fullname" . }}-patch-sa + {{- end }} --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding @@ -75,6 +77,7 @@ subjects: name: {{ include "drivers.fullname" . }}-patch-sa namespace: {{ .Release.Namespace }} --- +{{- if .Capabilities.APIVersions.Has "policy/v1beta1/PodSecurityPolicy" }} apiVersion: policy/v1beta1 kind: PodSecurityPolicy metadata: @@ -105,6 +108,7 @@ spec: readOnlyRootFilesystem: false volumes: - 'secret' +{{- end }} --- apiVersion: networking.k8s.io/v1 kind: NetworkPolicy