{{if .Values.identity -}} --- ### ### Identity Controller Service RBAC ### kind: ClusterRole apiVersion: rbac.authorization.k8s.io/v1 metadata: name: linkerd-{{.Values.namespace}}-identity labels: linkerd.io/control-plane-component: identity linkerd.io/control-plane-ns: {{.Values.namespace}} rules: - apiGroups: ["authentication.k8s.io"] resources: ["tokenreviews"] verbs: ["create"] - apiGroups: ["apps"] resources: ["deployments"] verbs: ["get"] - apiGroups: [""] resources: ["events"] verbs: ["create", "patch"] --- kind: ClusterRoleBinding apiVersion: rbac.authorization.k8s.io/v1 metadata: name: linkerd-{{.Values.namespace}}-identity labels: linkerd.io/control-plane-component: identity linkerd.io/control-plane-ns: {{.Values.namespace}} roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: linkerd-{{.Values.namespace}}-identity subjects: - kind: ServiceAccount name: linkerd-identity namespace: {{.Values.namespace}} --- kind: ServiceAccount apiVersion: v1 metadata: name: linkerd-identity namespace: {{.Values.namespace}} labels: linkerd.io/control-plane-component: identity linkerd.io/control-plane-ns: {{.Values.namespace}} {{- include "partials.image-pull-secrets" .Values.imagePullSecrets }} {{ end -}}