{{ if .Values.enablePSP -}} --- apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: name: psp namespace: {{ .Release.Namespace }} labels: linkerd.io/extension: jaeger {{- with .Values.commonLabels }}{{ toYaml . | trim | nindent 4 }}{{- end }} rules: - apiGroups: ['policy', 'extensions'] resources: ['podsecuritypolicies'] verbs: ['use'] resourceNames: - linkerd-{{.Values.linkerdNamespace}}-control-plane --- apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: jaeger-psp namespace: {{ .Release.Namespace }} labels: linkerd.io/extension: jaeger {{- with .Values.commonLabels }}{{ toYaml . | trim | nindent 4 }}{{- end }} roleRef: kind: Role name: psp apiGroup: rbac.authorization.k8s.io subjects: {{ if .Values.collector.enabled -}} - kind: ServiceAccount name: collector namespace: {{.Release.Namespace}} {{ end -}} - kind: ServiceAccount name: jaeger-injector namespace: {{.Release.Namespace}} {{ if .Values.jaeger.enabled -}} - kind: ServiceAccount name: jaeger namespace: {{.Release.Namespace}} {{ end -}} - kind: ServiceAccount name: namespace-metadata namespace: {{.Release.Namespace}} {{ end -}}