{{- if .Values.rbac.create }} apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: {{ template "coredns.fullname" . }} labels: app.kubernetes.io/managed-by: {{ .Release.Service | quote }} app.kubernetes.io/instance: {{ .Release.Name | quote }} helm.sh/chart: "{{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}" {{- if .Values.isClusterService }} k8s-app: {{ .Chart.Name | quote }} kubernetes.io/cluster-service: "true" kubernetes.io/name: "CoreDNS" {{- end }} app.kubernetes.io/name: {{ template "coredns.name" . }} roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: {{ template "coredns.fullname" . }} subjects: - kind: ServiceAccount name: {{ template "coredns.serviceAccountName" . }} namespace: {{ .Release.Namespace }} {{- end }}