role.yaml 684 B

12345678910111213141516171819202122232425262728293031
  1. {{- if or .Values.rbac.pspEnabled .Values.rbac.sccEnabled }}
  2. apiVersion: rbac.authorization.k8s.io/v1
  3. kind: Role
  4. metadata:
  5. name: {{ include "loki.fullname" . }}
  6. namespace: {{ .Release.Namespace }}
  7. labels:
  8. {{- include "loki.labels" . | nindent 4 }}
  9. {{- if .Values.rbac.pspEnabled }}
  10. rules:
  11. - apiGroups:
  12. - policy
  13. resources:
  14. - podsecuritypolicies
  15. verbs:
  16. - use
  17. resourceNames:
  18. - {{ include "loki.fullname" . }}
  19. {{- end }}
  20. {{- if .Values.rbac.sccEnabled }}
  21. rules:
  22. - apiGroups:
  23. - security.openshift.io
  24. resources:
  25. - securitycontextconstraints
  26. verbs:
  27. - use
  28. resourceNames:
  29. - {{ include "loki.fullname" . }}
  30. {{- end }}
  31. {{- end }}