diff --git a/secret-observer/secret-observer/helm-charts/secret-observer/templates/clusterrole.yaml b/secret-observer/secret-observer/helm-charts/secret-observer/templates/role.yaml similarity index 63% rename from secret-observer/secret-observer/helm-charts/secret-observer/templates/clusterrole.yaml rename to secret-observer/secret-observer/helm-charts/secret-observer/templates/role.yaml index 33827a3..9b4f3a4 100644 --- a/secret-observer/secret-observer/helm-charts/secret-observer/templates/clusterrole.yaml +++ b/secret-observer/secret-observer/helm-charts/secret-observer/templates/role.yaml @@ -1,16 +1,17 @@ {{/* # -# Copyright (c) 2021-2022 Wind River Systems, Inc. +# Copyright (c) 2021-2024 Wind River Systems, Inc. # # SPDX-License-Identifier: Apache-2.0 # */}} -{{- if .Values.clusterRole.create }} +{{- if .Values.Role.create }} apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRole +kind: Role metadata: - name: secret-observer-cr + namespace: "{{ .Values.namespace }}" + name: secret-observer-r labels: app: secret-observer release: "{{ .Release.Name }}" diff --git a/secret-observer/secret-observer/helm-charts/secret-observer/templates/clusterrolebinding.yaml b/secret-observer/secret-observer/helm-charts/secret-observer/templates/rolebinding.yaml similarity index 59% rename from secret-observer/secret-observer/helm-charts/secret-observer/templates/clusterrolebinding.yaml rename to secret-observer/secret-observer/helm-charts/secret-observer/templates/rolebinding.yaml index 7b97ff8..77aa588 100644 --- a/secret-observer/secret-observer/helm-charts/secret-observer/templates/clusterrolebinding.yaml +++ b/secret-observer/secret-observer/helm-charts/secret-observer/templates/rolebinding.yaml @@ -1,22 +1,23 @@ {{/* # -# Copyright (c) 2021 Wind River Systems, Inc. +# Copyright (c) 2021-2024 Wind River Systems, Inc. # # SPDX-License-Identifier: Apache-2.0 # */}} -{{- if .Values.clusterRoleBinding.create }} +{{- if .Values.RoleBinding.create }} apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRoleBinding +kind: RoleBinding metadata: + namespace: "{{ .Values.namespace }}" labels: release: "{{ .Release.Name }}" - name: secret-observer-crb + name: secret-observer-rb roleRef: apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: secret-observer-cr + kind: Role + name: secret-observer-r subjects: - kind: ServiceAccount name: secret-observer diff --git a/secret-observer/secret-observer/helm-charts/secret-observer/values.yaml b/secret-observer/secret-observer/helm-charts/secret-observer/values.yaml index f32a32c..9de9fb0 100644 --- a/secret-observer/secret-observer/helm-charts/secret-observer/values.yaml +++ b/secret-observer/secret-observer/helm-charts/secret-observer/values.yaml @@ -8,10 +8,10 @@ image: docker.io/curlimages/curl imageTag: 8.8.0 namespace: default -clusterRoleBinding: +RoleBinding: create: true -clusterRole: +Role: create: true serviceAccount: