cw-infra-apps/vault-secrets-operator/templates/hcpauth_editor_role.yaml

37 lines
846 B
YAML

{{- /*
# Copyright (c) HashiCorp, Inc.
# SPDX-License-Identifier: BUSL-1.1
# auto generated by sync-rbac.sh from ./config/rbac/hcpauth_editor_role.yaml -- do not edit
*/ -}}
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: {{ printf "%s-%s" (include "vso.chart.fullname" .) "hcpauth-editor-role" }}
labels:
app.kubernetes.io/component: rbac
# allow for selecting on the canonical name
vso.hashicorp.com/role-instance: hcpauth-editor-role
vso.hashicorp.com/aggregate-to-editor: "true"
{{- include "vso.chart.labels" . | nindent 4 }}
rules:
- apiGroups:
- secrets.hashicorp.com
resources:
- hcpauths
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- secrets.hashicorp.com
resources:
- hcpauths/status
verbs:
- get