Skip to content

Commit ab7765d

Browse files
authored
Add explicit enabled for script pod clusterrole (#496)
1 parent de26b67 commit ab7765d

File tree

4 files changed

+8
-2
lines changed

4 files changed

+8
-2
lines changed

.changeset/easy-sides-care.md

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"kubernetes-agent": minor
3+
---
4+
5+
Add explicit cluster role enabled value

charts/kubernetes-agent/templates/pod-clusterbinding.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
{{- if and (empty (include "kubernetes-agent.targetNamespaces" . | fromJsonArray)) (not .Values.agent.worker.enabled) (not .Values.scriptPods.serviceAccount.useNamespacedRoles) }}
1+
{{- if and .Values.scriptPods.serviceAccount.clusterRole.enabled (empty (include "kubernetes-agent.targetNamespaces" . | fromJsonArray)) (not .Values.agent.worker.enabled) (not .Values.scriptPods.serviceAccount.useNamespacedRoles) }}
22
apiVersion: rbac.authorization.k8s.io/v1
33
kind: ClusterRoleBinding
44
metadata:

charts/kubernetes-agent/templates/pod-clusterroles.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
{{- if not .Values.scriptPods.serviceAccount.useNamespacedRoles }}
1+
{{- if and .Values.scriptPods.serviceAccount.clusterRole.enabled (not .Values.scriptPods.serviceAccount.useNamespacedRoles)}}
22
apiVersion: rbac.authorization.k8s.io/v1
33
kind: ClusterRole
44
metadata:

charts/kubernetes-agent/values.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -233,6 +233,7 @@ scriptPods:
233233
# @section -- Script pod values
234234
# @default -- `[{"apiGroups":["*"],"resources":["*"],"verbs":["*"]},{"nonResourceURLs":["*"],"verbs":["*"]}]`
235235
clusterRole:
236+
enabled: true
236237
rules: []
237238

238239
# -- if defined, overrides the default Role rules when using namespace-scoped roles

0 commit comments

Comments
 (0)