44 lines
1.3 KiB
YAML
44 lines
1.3 KiB
YAML
##---
|
|
# Source: cert-manager/templates/rbac.yaml
|
|
apiVersion: rbac.authorization.k8s.io/v1beta1
|
|
kind: ClusterRole
|
|
metadata:
|
|
name: cert-manager
|
|
labels:
|
|
app: cert-manager
|
|
chart: cert-manager-0.2.3
|
|
release: cert-manager
|
|
heritage: Tiller
|
|
rules:
|
|
- apiGroups: ["certmanager.k8s.io"]
|
|
resources: ["certificates", "issuers", "clusterissuers"]
|
|
verbs: ["*"]
|
|
- apiGroups: [""]
|
|
# TODO: remove endpoints once 0.4 is released. We include it here in case
|
|
# users use the 'master' version of the Helm chart with a 0.2.x release of
|
|
# cert-manager that still performs leader election with Endpoint resources.
|
|
# We advise users don't do this, but some will anyway and this will reduce
|
|
# friction.
|
|
resources: ["endpoints", "configmaps", "secrets", "events", "services", "pods"]
|
|
verbs: ["*"]
|
|
- apiGroups: ["extensions"]
|
|
resources: ["ingresses"]
|
|
verbs: ["*"]
|
|
---
|
|
apiVersion: rbac.authorization.k8s.io/v1beta1
|
|
kind: ClusterRoleBinding
|
|
metadata:
|
|
name: cert-manager
|
|
labels:
|
|
app: cert-manager
|
|
chart: cert-manager-0.2.3
|
|
release: cert-manager
|
|
heritage: Tiller
|
|
roleRef:
|
|
apiGroup: rbac.authorization.k8s.io
|
|
kind: ClusterRole
|
|
name: cert-manager
|
|
subjects:
|
|
- name: cert-manager
|
|
namespace: "cert-manager"
|
|
kind: ServiceAccount |