role.yaml 769 B

123456789101112131415161718192021222324
  1. {{- if and .Values.controller.admissionWebhooks.enabled .Values.controller.admissionWebhooks.patch.enabled -}}
  2. apiVersion: rbac.authorization.k8s.io/v1
  3. kind: Role
  4. metadata:
  5. name: {{ include "ingress-nginx.fullname" . }}-admission
  6. namespace: {{ .Release.Namespace }}
  7. annotations:
  8. "helm.sh/hook": pre-install,pre-upgrade,post-install,post-upgrade
  9. "helm.sh/hook-delete-policy": before-hook-creation,hook-succeeded
  10. labels:
  11. {{- include "ingress-nginx.labels" . | nindent 4 }}
  12. app.kubernetes.io/component: admission-webhook
  13. {{- with .Values.controller.admissionWebhooks.patch.labels }}
  14. {{- toYaml . | nindent 4 }}
  15. {{- end }}
  16. rules:
  17. - apiGroups:
  18. - ""
  19. resources:
  20. - secrets
  21. verbs:
  22. - get
  23. - create
  24. {{- end }}