{{- if .Values.kubernetesIntegration }} apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: {{ include "authentik.fullname" . }}-sa-role rules: - apiGroups: - "" resources: - secrets - services verbs: - "get" - "create" - "delete" - "read" - "patch" - apiGroups: - "extensions" - "apps" resources: - "deployments" verbs: - "get" - "create" - "delete" - "read" - "patch" - apiGroups: - "extensions" - "networking.k8s.io" resources: - "ingresses" verbs: - "get" - "create" - "delete" - "read" - "patch" - apiGroups: - "" resources: - namespaces verbs: - list --- apiVersion: v1 kind: ServiceAccount metadata: name: {{ include "authentik.fullname" . }}-sa --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: {{ include "authentik.fullname" . }}-sa-role-binding roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: {{ include "authentik.fullname" . }}-sa-role subjects: - kind: ServiceAccount name: {{ include "authentik.fullname" . }}-sa namespace: {{ .Release.Namespace }} {{- end }}