{{- if ( and .Values.orchestrator.serviceAccount.enabled ( not .Values.orchestrator.serviceAccount.preexisting ) ) -}} apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: name: {{ template "orchestrator.name" . }}-role rules: - apiGroups: - "" resources: - pods verbs: - get - list {{- end }}