1 {{- if .Values.rbacEnable }}
2 # Grant the rook system daemons cluster-wide access to manage the Rook CRDs, PVCs, and storage classes
3 kind: ClusterRoleBinding
4 apiVersion: rbac.authorization.k8s.io/v1beta1
10 chart: "{{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}"
12 apiGroup: rbac.authorization.k8s.io
14 name: rook-ceph-global
16 - kind: ServiceAccount
17 name: rook-ceph-system
18 namespace: {{ .Release.Namespace }}
19 {{- if .Values.pspEnable }}
21 apiVersion: rbac.authorization.k8s.io/v1beta1
22 kind: ClusterRoleBinding
24 name: rook-ceph-system-psp-users
28 chart: "{{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}"
30 apiGroup: rbac.authorization.k8s.io
32 name: rook-ceph-system-psp-user
34 - kind: ServiceAccount
35 name: rook-ceph-system
36 namespace: {{ .Release.Namespace }}