{{- if .Values.apiportal.enabled -}} --- apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: name: apiportalscc namespace: {{ .Release.Namespace | quote }} labels: {{- include "gateway.labels" . | nindent 4 }} app.kubernetes.io/component: apiportal rules: - apiGroups: - security.openshift.io resourceNames: - nonroot resources: - securitycontextconstraints verbs: - use --- apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: apiportalscc namespace: {{ .Release.Namespace | quote }} labels: {{- include "gateway.labels" . | nindent 4 }} app.kubernetes.io/component: apiportal subjects: - kind: ServiceAccount name: {{ include "gateway.apiportal.serviceAccountName" . }} namespace: {{ .Release.Namespace | quote }} roleRef: kind: Role name: apiportalscc apiGroup: rbac.authorization.k8s.io {{- end }}