45 lines
822 B
YAML

{{- if .Values.serviceAccount.create -}}
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: {{ include "cluster-addons.fullname" . }}-manage-jobs
labels: {{ include "cluster-addons.labels" . | nindent 4 }}
rules:
- apiGroups:
- ""
resources:
- secrets
verbs:
- list
- get
- apiGroups:
- batch
resources:
- jobs
verbs:
- list
- get
- watch
- patch
{{- if .Values.clusterApi }}
- apiGroups:
- cluster.x-k8s.io
resources:
- clusters
verbs:
- list
- get
- watch
{{- if .Values.openstack.enabled }}
- apiGroups:
- infrastructure.cluster.x-k8s.io
resources:
- openstackclusters
verbs:
- list
- get
- watch
{{- end }}
{{- end }}
{{- end }}