{{- if .Values.rbac.create }} kind: ClusterRoleBinding apiVersion: rbac.authorization.k8s.io/v1 metadata: labels: app: {{ template "nfs-client-provisioner.name" . }} chart: {{ template "nfs-client-provisioner.chart" . }} heritage: {{ .Release.Service }} release: {{ .Release.Name }} name: run-{{ template "nfs-client-provisioner.fullname" . }} subjects: - kind: ServiceAccount name: {{ template "nfs-client-provisioner.serviceAccountName" . }} namespace: {{ .Release.Namespace }} roleRef: kind: ClusterRole name: {{ template "nfs-client-provisioner.fullname" . }}-runner apiGroup: rbac.authorization.k8s.io {{- end }}