init-service-account.yaml 5.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226
  1. ---
  2. apiVersion: v1
  3. kind: ServiceAccount
  4. metadata:
  5. name: {{ .Release.Name }}-init
  6. namespace: {{ .Release.Namespace }}
  7. annotations:
  8. "helm.sh/hook": pre-install,pre-upgrade,post-install,post-upgrade,post-delete
  9. "helm.sh/hook-delete-policy": before-hook-creation,hook-succeeded
  10. "helm.sh/hook-weight": "-100"
  11. {{- if or .Values.serviceAccount.repoCredentials .Values.imagePullSecrets }}
  12. imagePullSecrets:
  13. {{- with .Values.serviceAccount.repoCredentials }}
  14. {{- range . }}
  15. - name: {{ . }}
  16. {{- end }}
  17. {{- end }}
  18. {{- with .Values.imagePullSecrets }}
  19. {{ . | toYaml }}
  20. {{- end }}
  21. {{- end }}
  22. ---
  23. apiVersion: rbac.authorization.k8s.io/v1
  24. kind: ClusterRole
  25. metadata:
  26. annotations:
  27. "helm.sh/hook": pre-install,pre-upgrade,post-install,post-upgrade,post-delete
  28. "helm.sh/hook-delete-policy": before-hook-creation,hook-succeeded
  29. "helm.sh/hook-weight": "-100"
  30. name: {{ .Release.Name }}-init
  31. {{- with .Values.clusterOwnerRefereces }}
  32. ownerReferences:
  33. {{- toYaml . | nindent 4 }}
  34. {{- end }}
  35. rules:
  36. - apiGroups: ["apiextensions.k8s.io"]
  37. resources:
  38. - customresourcedefinitions
  39. verbs:
  40. - create
  41. - apiGroups: ["apiextensions.k8s.io"]
  42. resources:
  43. - customresourcedefinitions
  44. resourceNames:
  45. - sgconfigs.stackgres.io
  46. verbs:
  47. - get
  48. - update
  49. {{- if eq "true" (include "unmodificableWebapiAdminClusterRoleBinding" .) }}
  50. - apiGroups: ["rbac.authorization.k8s.io"]
  51. resources:
  52. - clusterrolebindings
  53. resourceNames:
  54. - stackgres-restapi-admin
  55. verbs:
  56. - get
  57. - delete
  58. {{- end }}
  59. {{- if .Values.allowedNamespaces }}
  60. {{- $allowedNamespaces := regexSplit " " (include "allowedNamespaces" .) -1 }}
  61. - apiGroups: [""]
  62. resources: ["namespaces"]
  63. verbs:
  64. - patch
  65. - get
  66. resourceNames:
  67. {{- with $allowedNamespaces }}
  68. {{ toYaml . | nindent 2 }}
  69. {{- end }}
  70. {{- end }}
  71. {{- if or .Values.disableClusterRole .Values.disableCrdsAndWebhooksUpdate }}
  72. - apiGroups: ["apiextensions.k8s.io"]
  73. resources:
  74. - customresourcedefinitions
  75. resourceNames:
  76. - sgconfigs.stackgres.io
  77. - sgclusters.stackgres.io
  78. - sginstanceprofiles.stackgres.io
  79. - sgpgconfigs.stackgres.io
  80. - sgpoolconfigs.stackgres.io
  81. - sgbackups.stackgres.io
  82. - sgbackupconfigs.stackgres.io
  83. - sgobjectstorages.stackgres.io
  84. - sgdbops.stackgres.io
  85. - sgdistributedlogs.stackgres.io
  86. - sgshardedclusters.stackgres.io
  87. - sgshardedbackups.stackgres.io
  88. - sgshardeddbops.stackgres.io
  89. - sgscripts.stackgres.io
  90. verbs:
  91. - get
  92. - patch
  93. - update
  94. - apiGroups:
  95. - stackgres.io
  96. resources:
  97. - sgclusters
  98. - sgpgconfigs
  99. - sginstanceprofiles
  100. - sgpoolconfigs
  101. - sgbackupconfigs
  102. - sgbackups
  103. - sgdistributedlogs
  104. - sgdbops
  105. - sgobjectstorages
  106. - sgscripts
  107. - sgshardedclusters
  108. - sgshardedbackups
  109. - sgshardeddbops
  110. - sgconfigs
  111. verbs:
  112. - get
  113. - list
  114. - update
  115. - patch
  116. - apiGroups:
  117. - admissionregistration.k8s.io
  118. resources:
  119. - mutatingwebhookconfigurations
  120. - validatingwebhookconfigurations
  121. resourceNames:
  122. - {{ .Release.Name }}
  123. verbs:
  124. - get
  125. - patch
  126. {{- end }}
  127. ---
  128. apiVersion: rbac.authorization.k8s.io/v1
  129. kind: ClusterRoleBinding
  130. metadata:
  131. name: {{ .Release.Name }}-init
  132. annotations:
  133. "helm.sh/hook": pre-install,pre-upgrade,post-install,post-upgrade,post-delete
  134. "helm.sh/hook-delete-policy": before-hook-creation,hook-succeeded
  135. "helm.sh/hook-weight": "-100"
  136. {{- with .Values.clusterOwnerRefereces }}
  137. ownerReferences:
  138. {{- toYaml . | nindent 4 }}
  139. {{- end }}
  140. subjects:
  141. - kind: ServiceAccount
  142. name: {{ .Release.Name }}-init
  143. namespace: {{ .Release.Namespace }}
  144. roleRef:
  145. kind: ClusterRole
  146. name: {{ .Release.Name }}-init
  147. apiGroup: rbac.authorization.k8s.io
  148. ---
  149. apiVersion: rbac.authorization.k8s.io/v1
  150. kind: Role
  151. metadata:
  152. annotations:
  153. "helm.sh/hook": pre-install,pre-upgrade,post-install,post-upgrade,post-delete
  154. "helm.sh/hook-delete-policy": before-hook-creation,hook-succeeded
  155. "helm.sh/hook-weight": "-100"
  156. name: {{ .Release.Name }}-init
  157. namespace: {{ .Release.Namespace }}
  158. rules:
  159. - apiGroups: ["stackgres.io"]
  160. resources:
  161. - sgconfigs
  162. verbs:
  163. - create
  164. - apiGroups: ["stackgres.io"]
  165. resources:
  166. - sgconfigs
  167. resourceNames:
  168. - {{ .Release.Name }}
  169. verbs:
  170. - get
  171. - update
  172. - patch
  173. - delete
  174. {{- if or .Values.disableClusterRole .Values.disableCrdsAndWebhooksUpdate }}
  175. - apiGroups:
  176. - ""
  177. resources:
  178. - secrets
  179. verbs:
  180. - create
  181. - apiGroups:
  182. - ""
  183. resources:
  184. - secrets
  185. resourceNames:
  186. - {{ default (.Values.cert).secretName (printf "%s-certs" .Release.Name) }}
  187. verbs:
  188. - get
  189. - apiGroups:
  190. - ""
  191. resources:
  192. - pods
  193. verbs:
  194. - get
  195. - apiGroups:
  196. - stackgres.io
  197. resources:
  198. - sgconfigs/status
  199. resourceNames:
  200. - {{ .Release.Name }}
  201. verbs:
  202. - update
  203. - patch
  204. {{- end }}
  205. ---
  206. apiVersion: rbac.authorization.k8s.io/v1
  207. kind: RoleBinding
  208. metadata:
  209. {{- with .Values.clusterOwnerRefereces }}
  210. ownerReferences:
  211. {{- toYaml . | nindent 4 }}
  212. {{- end }}
  213. name: {{ .Release.Name }}-init
  214. namespace: {{ .Release.Namespace }}
  215. annotations:
  216. "helm.sh/hook": pre-install,pre-upgrade,post-install,post-upgrade,post-delete
  217. "helm.sh/hook-delete-policy": before-hook-creation,hook-succeeded
  218. "helm.sh/hook-weight": "-100"
  219. subjects:
  220. - kind: ServiceAccount
  221. name: {{ .Release.Name }}-init
  222. namespace: {{ .Release.Namespace }}
  223. roleRef:
  224. kind: Role
  225. name: {{ .Release.Name }}-init
  226. apiGroup: rbac.authorization.k8s.io