ingress-nginx-helm/charts/ingress-nginx/templates/default-backend-role.yaml

23 lines
823 B
YAML
Raw Normal View History

2020-02-24 19:25:57 +00:00
{{- if and .Values.rbac.create .Values.podSecurityPolicy.enabled .Values.defaultBackend.enabled -}}
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
labels:
{{- include "ingress-nginx.labels" . | nindent 4 }}
app.kubernetes.io/component: default-backend
{{- with .Values.defaultBackend.labels }}
{{- toYaml . | nindent 4 }}
{{- end }}
name: {{ include "ingress-nginx.fullname" . }}-backend
namespace: {{ include "ingress-nginx.namespace" . }}
2020-02-24 19:25:57 +00:00
rules:
2020-03-02 14:49:26 +00:00
- apiGroups: [{{ template "podSecurityPolicy.apiGroup" . }}]
2020-02-24 19:25:57 +00:00
resources: ['podsecuritypolicies']
verbs: ['use']
2021-02-24 00:31:56 +00:00
{{- with .Values.defaultBackend.existingPsp }}
resourceNames: [{{ . }}]
{{- else }}
resourceNames: [{{ include "ingress-nginx.fullname" . }}-backend]
2021-02-24 00:31:56 +00:00
{{- end }}
2020-03-02 14:49:26 +00:00
{{- end }}