rbac
This commit is contained in:
@ -1,23 +1,23 @@
|
|||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: ClusterRole
|
kind: ClusterRole
|
||||||
metadata:
|
metadata:
|
||||||
name: dns-challenge-illium
|
name: cert-manager-lego-webhook-challenges
|
||||||
rules:
|
rules:
|
||||||
- apiGroups:
|
- apiGroups:
|
||||||
- "cert-manager.io"
|
- "cert-manager.io"
|
||||||
- "acme.cert-manager.io"
|
- "acme.cert-manager.io"
|
||||||
resources: ["ionos"]
|
resources: ["challenges"]
|
||||||
verbs: ["*"]
|
verbs: ["*"]
|
||||||
---
|
---
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: ClusterRoleBinding
|
kind: ClusterRoleBinding
|
||||||
metadata:
|
metadata:
|
||||||
name: dns-challenge-illium-binding
|
name: ert-manager-lego-webhook-challenges-binding
|
||||||
roleRef:
|
roleRef:
|
||||||
apiGroup: rbac.authorization.k8s.io
|
apiGroup: rbac.authorization.k8s.io
|
||||||
kind: ClusterRole
|
kind: ClusterRole
|
||||||
name: dns-challenge-illium
|
name: cert-manager-lego-webhook-challenges
|
||||||
subjects:
|
subjects:
|
||||||
- kind: ServiceAccount
|
- kind: ServiceAccount
|
||||||
name: cert-manager
|
name: cert-manager
|
||||||
namespace: cert-manager
|
namespace: cert-manager-lego-webhook
|
@ -10,7 +10,7 @@ resources:
|
|||||||
- wildcard-cert.yaml
|
- wildcard-cert.yaml
|
||||||
- dns-issuer.yaml
|
- dns-issuer.yaml
|
||||||
- ionos-secret-sealed.yaml
|
- ionos-secret-sealed.yaml
|
||||||
# - additional-roles.yaml
|
- additional-roles.yaml
|
||||||
- https://github.com/cert-manager/cert-manager/releases/download/v1.14.4/cert-manager.crds.yaml
|
- https://github.com/cert-manager/cert-manager/releases/download/v1.14.4/cert-manager.crds.yaml
|
||||||
- namespace.yaml
|
- namespace.yaml
|
||||||
|
|
||||||
|
@ -5,5 +5,5 @@ webhook:
|
|||||||
tag: main
|
tag: main
|
||||||
|
|
||||||
certManager:
|
certManager:
|
||||||
namespace: 'cert-manager'
|
namespace: cert-manager
|
||||||
serviceAccountName: cert-manager
|
# serviceAccountName: cert-manager
|
||||||
|
Reference in New Issue
Block a user