# bind that role to the webhook's service account kind: ClusterRoleBinding apiVersion: rbac.authorization.k8s.io/v1 metadata: name: {{ .Release.Name }} labels: {{ include "gmsa.chartref" . | nindent 4 }} subjects: - kind: ServiceAccount name: {{ .Release.Name }} namespace: {{ .Release.Namespace }} roleRef: kind: ClusterRole name: {{ .Release.Name }} apiGroup: rbac.authorization.k8s.io