diff --git a/contrib/manifests/cert-manager/with-rbac.yaml b/contrib/manifests/cert-manager/with-rbac.yaml index fe371d2ff..e3d5ae725 100644 --- a/contrib/manifests/cert-manager/with-rbac.yaml +++ b/contrib/manifests/cert-manager/with-rbac.yaml @@ -18,7 +18,7 @@ metadata: namespace: "cert-manager" labels: app: cert-manager - chart: cert-manager-v0.6.0-dev.0 + chart: cert-manager-v0.6.0-dev.1 release: cert-manager heritage: Tiller --- @@ -31,7 +31,7 @@ metadata: "helm.sh/hook": crd-install labels: app: cert-manager - chart: cert-manager-v0.6.0-dev.0 + chart: cert-manager-v0.6.0-dev.1 release: cert-manager heritage: Tiller spec: @@ -55,7 +55,7 @@ metadata: "helm.sh/hook": crd-install labels: app: cert-manager - chart: cert-manager-v0.6.0-dev.0 + chart: cert-manager-v0.6.0-dev.1 release: cert-manager heritage: Tiller spec: @@ -75,7 +75,7 @@ metadata: "helm.sh/hook": crd-install labels: app: cert-manager - chart: cert-manager-v0.6.0-dev.0 + chart: cert-manager-v0.6.0-dev.1 release: cert-manager heritage: Tiller spec: @@ -93,7 +93,7 @@ metadata: name: cert-manager labels: app: cert-manager - chart: cert-manager-v0.6.0-dev.0 + chart: cert-manager-v0.6.0-dev.1 release: cert-manager heritage: Tiller rules: @@ -113,7 +113,7 @@ metadata: name: cert-manager labels: app: cert-manager - chart: cert-manager-v0.6.0-dev.0 + chart: cert-manager-v0.6.0-dev.1 release: cert-manager heritage: Tiller roleRef: @@ -125,6 +125,39 @@ subjects: namespace: "cert-manager" kind: ServiceAccount --- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: cert-manager-view + labels: + app: cert-manager + chart: cert-manager-v0.6.0-dev.1 + release: cert-manager + heritage: Tiller + rbac.authorization.k8s.io/aggregate-to-view: "true" + rbac.authorization.k8s.io/aggregate-to-edit: "true" + rbac.authorization.k8s.io/aggregate-to-admin: "true" +rules: + - apiGroups: ["certmanager.k8s.io"] + resources: ["certificates", "issuers"] + verbs: ["get", "list", "watch"] +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: cert-manager-edit + labels: + app: cert-manager + chart: cert-manager-v0.6.0-dev.1 + release: cert-manager + heritage: Tiller + rbac.authorization.k8s.io/aggregate-to-edit: "true" + rbac.authorization.k8s.io/aggregate-to-admin: "true" +rules: + - apiGroups: ["certmanager.k8s.io"] + resources: ["certificates", "issuers"] + verbs: ["create", "delete", "deletecollection", "patch", "update"] +--- # Source: cert-manager/templates/deployment.yaml apiVersion: apps/v1beta1 kind: Deployment @@ -133,7 +166,7 @@ metadata: namespace: "cert-manager" labels: app: cert-manager - chart: cert-manager-v0.6.0-dev.0 + chart: cert-manager-v0.6.0-dev.1 release: cert-manager heritage: Tiller spec: diff --git a/contrib/manifests/cert-manager/without-rbac.yaml b/contrib/manifests/cert-manager/without-rbac.yaml index 8dad7b541..c6ce23ea5 100644 --- a/contrib/manifests/cert-manager/without-rbac.yaml +++ b/contrib/manifests/cert-manager/without-rbac.yaml @@ -19,7 +19,7 @@ metadata: "helm.sh/hook": crd-install labels: app: cert-manager - chart: cert-manager-v0.6.0-dev.0 + chart: cert-manager-v0.6.0-dev.1 release: cert-manager heritage: Tiller spec: @@ -43,7 +43,7 @@ metadata: "helm.sh/hook": crd-install labels: app: cert-manager - chart: cert-manager-v0.6.0-dev.0 + chart: cert-manager-v0.6.0-dev.1 release: cert-manager heritage: Tiller spec: @@ -63,7 +63,7 @@ metadata: "helm.sh/hook": crd-install labels: app: cert-manager - chart: cert-manager-v0.6.0-dev.0 + chart: cert-manager-v0.6.0-dev.1 release: cert-manager heritage: Tiller spec: @@ -82,7 +82,7 @@ metadata: namespace: "cert-manager" labels: app: cert-manager - chart: cert-manager-v0.6.0-dev.0 + chart: cert-manager-v0.6.0-dev.1 release: cert-manager heritage: Tiller spec: