Skip to content

Commit f6b6746

Browse files
belfhiJohannes Reppin
authored andcommitted
change ServiceAccount RBAC to Role & ClusterRole
Signed-off-by: Johannes Reppin <johannes.reppin@desy.de>
1 parent 7e6930a commit f6b6746

File tree

1 file changed

+5
-4
lines changed

1 file changed

+5
-4
lines changed

charts/keycloakx/templates/serviceaccount.yaml

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -20,24 +20,25 @@ imagePullSecrets:
2020
automountServiceAccountToken: {{ .Values.serviceAccount.automountServiceAccountToken }}
2121

2222
---
23-
2423
{{- if .Values.serviceAccount.allowReadPods -}}
25-
kind: ClusterRole
24+
kind: Role
2625
apiVersion: rbac.authorization.k8s.io/v1
2726
metadata:
2827
name: jgroups-kubeping-pod-reader-{{ .Release.Namespace }}
28+
namespace: {{ .Release.Namespace }}
2929
rules:
3030
- apiGroups: [""]
3131
resources: ["pods"]
3232
verbs: ["get", "list"]
3333
---
3434
apiVersion: rbac.authorization.k8s.io/v1
35-
kind: ClusterRoleBinding
35+
kind: RoleBinding
3636
metadata:
3737
name: jgroups-kubeping-api-access-{{ .Release.Namespace }}
38+
namespace: {{ .Release.Namespace }}
3839
roleRef:
3940
apiGroup: rbac.authorization.k8s.io
40-
kind: ClusterRole
41+
kind: Role
4142
name: jgroups-kubeping-pod-reader-{{ .Release.Namespace }}
4243
subjects:
4344
- kind: ServiceAccount

0 commit comments

Comments
 (0)