{{- if .Values.rbacEnable }} # Grant the rook system daemons cluster-wide access to manage the Rook CRDs, PVCs, and storage classes kind: ClusterRoleBinding apiVersion: rbac.authorization.k8s.io/v1beta1 metadata: name: rook-ceph-global labels: operator: rook storage-backend: ceph chart: "{{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}" roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: rook-ceph-global subjects: - kind: ServiceAccount name: rook-ceph-system namespace: {{ .Release.Namespace }} {{- if .Values.pspEnable }} --- apiVersion: rbac.authorization.k8s.io/v1beta1 kind: ClusterRoleBinding metadata: name: rook-ceph-system-psp-users labels: operator: rook storage-backend: ceph chart: "{{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}" roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: rook-ceph-system-psp-user subjects: - kind: ServiceAccount name: rook-ceph-system namespace: {{ .Release.Namespace }} {{- end }} {{- end }}