Files
harmony/iot/iot-operator-v0/chart/templates/clusterrolebinding.yaml
Jean-Gabriel Gill-Couture 99e661ce4d
All checks were successful
Run Check Script / check (pull_request) Successful in 2m44s
feat(iot-operator): helm chart + gen-chart-crd subcommand
Chapter 3 scaffolding. Chart layout mirrors the CloudNativePG
convention after reviewing the CRD-in-chart vs CRD-as-hook
tradeoff: CRDs live inside templates/ (so helm upgrade re-applies
schema changes) with helm.sh/resource-policy: keep so
helm uninstall never deletes them. Chart publication target is
hub.nationtech.io.

CRD yaml is generated at chart-release time by a new
`iot-operator-v0 gen-chart-crd` subcommand reading
Deployment::crd() — the runtime install path remains the typed
Score; only the chart deliverable uses generated yaml. Wrapped
with the helm conditional + annotations by templates/crds.yaml
via .Files.Get so the generated yaml stays pure.

Install / upgrade / uninstall-preserves-CRD validated against a
scratch k3d cluster; the operator pod naturally stays pending
because the hub.nationtech.io image hasn't been published yet.
2026-04-21 23:33:06 -04:00

17 lines
494 B
YAML

{{- if .Values.rbac.create -}}
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: {{ include "iot-operator-v0.fullname" . }}
labels:
{{- include "iot-operator-v0.labels" . | nindent 4 }}
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: {{ include "iot-operator-v0.fullname" . }}
subjects:
- kind: ServiceAccount
name: {{ include "iot-operator-v0.serviceAccountName" . }}
namespace: {{ .Release.Namespace }}
{{- end -}}