@@ -6,6 +6,7 @@ apiVersion: v1
66kind : ServiceAccount
77metadata :
88 name : {{ printf "%s-issuer" $fullname }}
9+ namespace : {{ .Release.Namespace }}
910 labels :
1011 {{- include "ggbridge.labels" . | nindent 4 }}
1112 {{- if or .Values.commonAnnotations .Values.serviceAccount.annotations }}
@@ -18,6 +19,8 @@ kind: Role
1819metadata :
1920 name : {{ printf "%s-issuer" $fullname }}
2021 namespace : {{ .Release.Namespace }}
22+ labels :
23+ {{- include "ggbridge.labels" . | nindent 4 }}
2124rules :
2225 - apiGroups : ['']
2326 resources : ['serviceaccounts/token']
@@ -29,10 +32,17 @@ kind: RoleBinding
2932metadata :
3033 name : {{ printf "%s-issuer" $fullname }}
3134 namespace : {{ .Release.Namespace }}
35+ labels :
36+ {{- include "ggbridge.labels" . | nindent 4 }}
3237subjects :
3338 - kind : ServiceAccount
3439 name : {{ .Values.tls.certManager.serviceAccount }}
3540 namespace : {{ .Values.tls.certManager.namespace }}
41+ {{- if .Values.tls.certManager.issuer.spec.vault.auth.kubernetes.serviceAccountRef }}
42+ - kind : ServiceAccount
43+ name : {{ .Values.tls.certManager.issuer.spec.vault.auth.kubernetes.serviceAccountRef.name }}
44+ namespace : {{ .Release.Namespace }}
45+ {{- end }}
3646roleRef :
3747 apiGroup : rbac.authorization.k8s.io
3848 kind : Role
@@ -42,6 +52,9 @@ apiVersion: v1
4252kind : Secret
4353metadata :
4454 name : {{ printf "%s-issuer-token" $fullname }}
55+ namespace : {{ .Release.Namespace }}
56+ labels :
57+ {{- include "ggbridge.labels" . | nindent 4 }}
4558 annotations :
4659 kubernetes.io/service-account.name : {{ printf "%s-issuer" $fullname }}
4760type : kubernetes.io/service-account-token
@@ -50,6 +63,8 @@ apiVersion: rbac.authorization.k8s.io/v1
5063kind : ClusterRoleBinding
5164metadata :
5265 name : {{ printf "%s-issuer" $fullname }}-token-reviewer
66+ labels :
67+ {{- include "ggbridge.labels" . | nindent 4 }}
5368roleRef :
5469 apiGroup : rbac.authorization.k8s.io
5570 kind : ClusterRole
@@ -66,6 +81,8 @@ kind: Role
6681metadata :
6782 name : {{ printf "%s-cert-manager" $fullname }}
6883 namespace : {{ .Release.Namespace }}
84+ labels :
85+ {{- include "ggbridge.labels" . | nindent 4 }}
6986rules :
7087 - apiGroups :
7188 - ' '
@@ -99,6 +116,8 @@ kind: RoleBinding
99116metadata :
100117 name : {{ printf "%s-cert-manager" $fullname }}
101118 namespace : {{ .Release.Namespace }}
119+ labels :
120+ {{- include "ggbridge.labels" . | nindent 4 }}
102121roleRef :
103122 apiGroup : rbac.authorization.k8s.io
104123 kind : Role
0 commit comments