From 38d431ec77e30b05cf1ce4b4a81b61999ab35512 Mon Sep 17 00:00:00 2001 From: Sheen Capadngan Date: Tue, 21 Jan 2025 23:57:11 +0800 Subject: [PATCH] misc: added more scoping logic for namespace installation --- helm-charts/secrets-operator/Chart.yaml | 4 ++-- .../secrets-operator/templates/metrics-reader-rbac.yaml | 4 +++- helm-charts/secrets-operator/templates/proxy-rbac.yaml | 4 +++- helm-charts/secrets-operator/values.yaml | 2 +- 4 files changed, 9 insertions(+), 5 deletions(-) diff --git a/helm-charts/secrets-operator/Chart.yaml b/helm-charts/secrets-operator/Chart.yaml index b7965268e..92a661165 100644 --- a/helm-charts/secrets-operator/Chart.yaml +++ b/helm-charts/secrets-operator/Chart.yaml @@ -13,9 +13,9 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: v0.8.4 +version: v0.8.5 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to # follow Semantic Versioning. They should reflect the version the application is using. # It is recommended to use it with quotes. -appVersion: "v0.8.4" +appVersion: "v0.8.5" diff --git a/helm-charts/secrets-operator/templates/metrics-reader-rbac.yaml b/helm-charts/secrets-operator/templates/metrics-reader-rbac.yaml index 7d7ceba46..eec9e5bee 100644 --- a/helm-charts/secrets-operator/templates/metrics-reader-rbac.yaml +++ b/helm-charts/secrets-operator/templates/metrics-reader-rbac.yaml @@ -1,3 +1,4 @@ +{{- if not .Values.scopedNamespace }} apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: @@ -11,4 +12,5 @@ rules: - nonResourceURLs: - /metrics verbs: - - get \ No newline at end of file + - get +{{- end }} \ No newline at end of file diff --git a/helm-charts/secrets-operator/templates/proxy-rbac.yaml b/helm-charts/secrets-operator/templates/proxy-rbac.yaml index 5f07e2908..28b8f4e7d 100644 --- a/helm-charts/secrets-operator/templates/proxy-rbac.yaml +++ b/helm-charts/secrets-operator/templates/proxy-rbac.yaml @@ -1,3 +1,4 @@ +{{- if not .Values.scopedNamespace }} apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: @@ -37,4 +38,5 @@ roleRef: subjects: - kind: ServiceAccount name: '{{ include "secrets-operator.fullname" . }}-controller-manager' - namespace: '{{ .Release.Namespace }}' \ No newline at end of file + namespace: '{{ .Release.Namespace }}' +{{- end }} \ No newline at end of file diff --git a/helm-charts/secrets-operator/values.yaml b/helm-charts/secrets-operator/values.yaml index bdcff101b..04ec63540 100644 --- a/helm-charts/secrets-operator/values.yaml +++ b/helm-charts/secrets-operator/values.yaml @@ -32,7 +32,7 @@ controllerManager: - ALL image: repository: infisical/kubernetes-operator - tag: v0.8.4 + tag: v0.8.5 resources: limits: cpu: 500m