apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: {{ include "falcon-sensor.fullname" . }}-access-binding labels: app: {{ include "falcon-sensor.name" . }} app.kubernetes.io/name: {{ include "falcon-sensor.name" . }} app.kubernetes.io/instance: {{ .Release.Name }} app.kubernetes.io/managed-by: {{ .Release.Service }} app.kubernetes.io/component: "container_sensor" crowdstrike.com/provider: crowdstrike helm.sh/chart: {{ include "falcon-sensor.chart" . }} subjects: {{- if .Values.container.enabled }} - apiGroup: rbac.authorization.k8s.io kind: Group name: system:authenticated {{- end }} - kind: ServiceAccount name: {{ .Values.serviceAccount.name }} namespace: {{ .Release.Namespace }} roleRef: kind: ClusterRole name: {{ include "falcon-sensor.fullname" . }}-access-role apiGroup: rbac.authorization.k8s.io