aboutsummaryrefslogtreecommitdiffstats
path: root/kud/demo/composite-firewall/sink/templates/rolebinding.yaml
diff options
context:
space:
mode:
authorEric Multanen <eric.w.multanen@intel.com>2021-06-24 20:35:52 +0000
committerGerrit Code Review <gerrit@onap.org>2021-06-24 20:35:52 +0000
commit40e13a3001826fbc1682dad51e5c1366aa62581e (patch)
tree67bfaf5a2d0337b00f87e3302ce11a946408d2f2 /kud/demo/composite-firewall/sink/templates/rolebinding.yaml
parent47b2506e0faa431a32222adb0ffb9fcddb763293 (diff)
parent225885f76eef52ac1b7d14353833d0b318359d9c (diff)
Merge "The sink app needs the CAP_NET_RAW capability"
Diffstat (limited to 'kud/demo/composite-firewall/sink/templates/rolebinding.yaml')
-rw-r--r--kud/demo/composite-firewall/sink/templates/rolebinding.yaml14
1 files changed, 14 insertions, 0 deletions
diff --git a/kud/demo/composite-firewall/sink/templates/rolebinding.yaml b/kud/demo/composite-firewall/sink/templates/rolebinding.yaml
new file mode 100644
index 00000000..14c5b758
--- /dev/null
+++ b/kud/demo/composite-firewall/sink/templates/rolebinding.yaml
@@ -0,0 +1,14 @@
+{{- if .Values.rbac.create }}
+apiVersion: rbac.authorization.k8s.io/v1
+kind: RoleBinding
+metadata:
+ name: {{ include "sink.fullname" . }}
+roleRef:
+ apiGroup: rbac.authorization.k8s.io
+ kind: ClusterRole
+ name: psp:privileged
+subjects:
+- kind: ServiceAccount
+ name: {{ include "sink.serviceAccountName" . }}
+ namespace: {{ $.Release.Namespace }}
+{{- end }}