Skip to content

Commit ce5d794

Browse files
committed
Add tokenreviews permissions
1 parent 4107d50 commit ce5d794

File tree

2 files changed

+7
-0
lines changed

2 files changed

+7
-0
lines changed

charts/eks-pod-identity-agent/templates/serviceaccount.yaml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,11 @@ rules:
2020
resources: ["serviceaccounts"]
2121
verbs: {{ .Values.irsa.cluster_role.permissions.serviceaccounts.verbs }}
2222
{{- end }}
23+
{{- if .Values.irsa.cluster_role.permissions.tokenreviews.verbs }}
24+
- apiGroups: ["authentication.k8s.io"]
25+
resources: ["tokenreviews"]
26+
verbs: {{ .Values.irsa.cluster_role.permissions.tokenreviews.verbs }}
27+
{{- end }}
2328
---
2429
apiVersion: rbac.authorization.k8s.io/v1
2530
kind: ClusterRoleBinding

charts/eks-pod-identity-agent/values.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -107,3 +107,5 @@ irsa:
107107
permissions:
108108
serviceaccounts:
109109
verbs: ["get"]
110+
tokenreviews:
111+
verbs: ["create"]

0 commit comments

Comments
 (0)