{{- if .Values.rbac.create }} kind: Role apiVersion: rbac.authorization.k8s.io/v1 metadata: name: {{ include "nginx-ingress.fullname" . }} labels: {{- include "nginx-ingress.labels" . | nindent 4 }} namespace: {{ .Release.Namespace }} rules: - apiGroups: - "" resources: - configmaps - pods - secrets - services verbs: - get - list - watch - apiGroups: - "" resources: - namespaces verbs: - get - apiGroups: - "" resources: - pods verbs: - update - apiGroups: - "" resources: - events verbs: - create - patch - list - apiGroups: - coordination.k8s.io resources: - leases resourceNames: - {{ .Values.controller.reportIngressStatus.leaderElectionLockName }} verbs: - get - update - apiGroups: - coordination.k8s.io resources: - leases verbs: - create {{- end }}