blob: 768dd39b56b3b5e6e40eac675117dab3d387432c [file] [log] [blame]
Mohammed Naser8a2c8fb2023-02-19 17:23:55 +00001{{- if or .Values.rbac.pspEnabled .Values.rbac.sccEnabled }}
2apiVersion: rbac.authorization.k8s.io/v1
3kind: Role
4metadata:
5 name: {{ include "loki.name" . }}
6 namespace: {{ .Release.Namespace }}
7 labels:
8 {{- include "loki.labels" . | nindent 4 }}
9{{- if .Values.rbac.pspEnabled }}
10rules:
11 - apiGroups:
12 - policy
13 resources:
14 - podsecuritypolicies
15 verbs:
16 - use
17 resourceNames:
18 - {{ include "loki.fullname" . }}
19{{- end }}
20{{- if .Values.rbac.sccEnabled }}
21rules:
22 - apiGroups:
23 - security.openshift.io
24 resources:
25 - securitycontextconstraints
26 verbs:
27 - use
28 resourceNames:
29 - {{ include "loki.fullname" . }}
30{{- end }}
31{{- end }}