Skip to content

Commit

Permalink
Make cluster deploy role name unique per namespace (#215)
Browse files Browse the repository at this point in the history
  • Loading branch information
OlamideOl1 authored Oct 30, 2024
1 parent ee488ad commit 5aa7945
Showing 1 changed file with 5 additions and 6 deletions.
11 changes: 5 additions & 6 deletions aws/deploy-role-bindings/main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ resource "kubernetes_cluster_role_binding" "cluster" {
for_each = toset(var.cluster_roles)

metadata {
name = var.name
name = "${var.name}-${var.namespace}"
}

role_ref {
Expand All @@ -20,7 +20,8 @@ resource "kubernetes_cluster_role_binding" "cluster" {

resource "kubernetes_cluster_role" "cluster_crd" {
metadata {
name = "${var.name}-cluster-crd"
name = "${var.name}-${var.namespace}-crd"

}

rule {
Expand All @@ -32,22 +33,20 @@ resource "kubernetes_cluster_role" "cluster_crd" {

resource "kubernetes_cluster_role_binding" "cluster_crd" {
metadata {
name = "${var.name}-cluster-crd"
name = "${var.name}-${var.namespace}-crd"
}

role_ref {
api_group = "rbac.authorization.k8s.io"
kind = "ClusterRole"
name = "${var.name}-cluster-crd"
name = kubernetes_cluster_role.cluster_crd.metadata[0].name
}

subject {
kind = "Group"
name = var.group
api_group = "rbac.authorization.k8s.io"
}

depends_on = [kubernetes_cluster_role.cluster_crd]
}

resource "kubernetes_role_binding" "crd" {
Expand Down

0 comments on commit 5aa7945

Please sign in to comment.