{{- if .Values.rbac.create -}} apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: {{ printf "system:%s" (include "metrics-server.fullname" .) }} labels: {{- include "metrics-server.labels" . | nindent 4 }} rules: - apiGroups: - "" resources: - nodes/metrics verbs: - get - apiGroups: - "" resources: - pods - nodes - namespaces - configmaps verbs: - get - list - watch {{- if .Values.rbac.pspEnabled }} - apiGroups: - extensions - policy resources: - podsecuritypolicies resourceNames: - {{ printf "privileged-%s" (include "metrics-server.fullname" .) }} verbs: - use {{- end -}} {{- end -}}