rancher-partner-charts/charts/aquarist-labs/s3gw/templates/cosi-rbac.yaml

61 lines
1.3 KiB
YAML

{{- if .Values.cosi.enabled }}
---
kind: ClusterRole
apiVersion: rbac.authorization.k8s.io/v1
metadata:
name: {{ include "s3gw-cosi.ClusterRoleName" . }}
labels:
{{ include "s3gw.labels" . | indent 4 }}
rules:
- apiGroups: ["objectstorage.k8s.io"]
resources:
- "buckets"
- "bucketaccesses"
- "bucketclaims"
- "bucketaccessclasses"
- "buckets/status"
- "bucketaccesses/status"
- "bucketclaims/status"
- "bucketaccessclasses/status"
verbs:
- "get"
- "list"
- "watch"
- "update"
- "create"
- "delete"
- apiGroups: ["coordination.k8s.io"]
resources: ["leases"]
verbs:
- "get"
- "watch"
- "list"
- "delete"
- "update"
- "create"
- apiGroups: [""]
resources:
- "secrets"
- "events"
verbs:
- "get"
- "delete"
- "update"
- "create"
---
kind: ClusterRoleBinding
apiVersion: rbac.authorization.k8s.io/v1
metadata:
name: {{ include "s3gw-cosi.ClusterRoleBindingName" . }}
labels:
{{ include "s3gw.labels" . | indent 4 }}
subjects:
- kind: ServiceAccount
name: {{ include "s3gw-cosi.ServiceAccountName" . }}
namespace: {{ .Release.Namespace }}
roleRef:
kind: ClusterRole
name: {{ include "s3gw-cosi.ClusterRoleName" . }}
apiGroup: rbac.authorization.k8s.io
{{- end }}