diff --git a/charts/cbcontainers-operator/cbcontainers-operator-chart/templates/operator.yaml b/charts/cbcontainers-operator/cbcontainers-operator-chart/templates/operator.yaml index ed97aef4..935a785c 100644 --- a/charts/cbcontainers-operator/cbcontainers-operator-chart/templates/operator.yaml +++ b/charts/cbcontainers-operator/cbcontainers-operator-chart/templates/operator.yaml @@ -4496,6 +4496,7 @@ kind: ServiceAccount metadata: name: cbcontainers-operator namespace: cbcontainers-dataplane +{{- if and (eq (int .Capabilities.KubeVersion.Major) 1) (lt (int .Capabilities.KubeVersion.Minor) 25) }} --- apiVersion: policy/v1beta1 kind: PodSecurityPolicy @@ -4519,6 +4520,7 @@ spec: rule: RunAsAny volumes: - '*' +{{- end }} --- apiVersion: rbac.authorization.k8s.io/v1 kind: Role diff --git a/config/rbac/kustomization.yaml b/config/rbac/kustomization.yaml index 28af6490..40dca000 100644 --- a/config/rbac/kustomization.yaml +++ b/config/rbac/kustomization.yaml @@ -12,4 +12,3 @@ resources: - auth_proxy_role.yaml - auth_proxy_role_binding.yaml # - auth_proxy_client_clusterrole.yaml -- pod_security_policy.yaml diff --git a/config/rbac/pod_security_policy.yaml b/operator_psp.yaml similarity index 91% rename from config/rbac/pod_security_policy.yaml rename to operator_psp.yaml index df0782fb..2fdcb8a3 100644 --- a/config/rbac/pod_security_policy.yaml +++ b/operator_psp.yaml @@ -2,7 +2,7 @@ apiVersion: policy/v1beta1 kind: PodSecurityPolicy metadata: - name: manager-psp + name: cbcontainers-manager-psp spec: privileged: true hostPID: true