2
0

role.yaml 1.2 KB

1234567891011121314151617181920212223242526272829303132
  1. {{- if and .Values.rbac.create (not .Values.rbac.useExistingRole) -}}
  2. apiVersion: {{ template "grafana.rbac.apiVersion" . }}
  3. kind: Role
  4. metadata:
  5. name: {{ template "grafana.fullname" . }}
  6. namespace: {{ template "grafana.namespace" . }}
  7. labels:
  8. {{- include "grafana.labels" . | nindent 4 }}
  9. {{- with .Values.annotations }}
  10. annotations:
  11. {{ toYaml . | indent 4 }}
  12. {{- end }}
  13. {{- if or .Values.rbac.pspEnabled (and .Values.rbac.namespaced (or .Values.sidecar.dashboards.enabled (or .Values.sidecar.datasources.enabled (or .Values.sidecar.plugins.enabled .Values.rbac.extraRoleRules)))) }}
  14. rules:
  15. {{- if .Values.rbac.pspEnabled }}
  16. - apiGroups: ['extensions']
  17. resources: ['podsecuritypolicies']
  18. verbs: ['use']
  19. resourceNames: [{{ template "grafana.fullname" . }}]
  20. {{- end }}
  21. {{- if and .Values.rbac.namespaced (or .Values.sidecar.dashboards.enabled (or .Values.sidecar.datasources.enabled .Values.sidecar.plugins.enabled)) }}
  22. - apiGroups: [""] # "" indicates the core API group
  23. resources: ["configmaps", "secrets"]
  24. verbs: ["get", "watch", "list"]
  25. {{- end }}
  26. {{- with .Values.rbac.extraRoleRules }}
  27. {{ toYaml . | indent 0 }}
  28. {{- end}}
  29. {{- else }}
  30. rules: []
  31. {{- end }}
  32. {{- end }}