Skip to content

Commit e23e6b9

Browse files
wip
1 parent fa50226 commit e23e6b9

File tree

1 file changed

+30
-0
lines changed

1 file changed

+30
-0
lines changed

charts/gitops-runtime/templates/_components/gitops-operator/rbac/_restricted_git_source.rbac.yaml

Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -47,4 +47,34 @@ rules:
4747
- restrictedgitsources/status
4848
verbs:
4949
- get
50+
---
51+
apiVersion: rbac.authorization.k8s.io/v1
52+
kind: ClusterRoleBinding
53+
metadata:
54+
labels:
55+
{{- include "gitops-operator.selectorLabels" . | nindent 4 }}
56+
name: restrictedgitsource-editor
57+
roleRef:
58+
apiGroup: rbac.authorization.k8s.io
59+
kind: ClusterRole
60+
name: restrictedgitsource-editor
61+
subjects:
62+
- kind: ServiceAccount
63+
name: {{ include "gitops-operator.serviceAccountName" . }}
64+
namespace: {{ .Release.Namespace }}
65+
---
66+
apiVersion: rbac.authorization.k8s.io/v1
67+
kind: ClusterRoleBinding
68+
metadata:
69+
labels:
70+
{{- include "gitops-operator.selectorLabels" . | nindent 4 }}
71+
name: restrictedgitsource-viewer
72+
roleRef:
73+
apiGroup: rbac.authorization.k8s.io
74+
kind: ClusterRole
75+
name: restrictedgitsource-viewer
76+
subjects:
77+
- kind: ServiceAccount
78+
name: {{ include "gitops-operator.serviceAccountName" . }}
79+
namespace: {{ .Release.Namespace }}
5080
{{- end }}

0 commit comments

Comments
 (0)