@@ -109,6 +109,13 @@ metadata:
109109 name : imperative-sa
110110 namespace : imperative
111111---
112+ # Source: clustergroup/templates/imperative/serviceaccount.yaml
113+ apiVersion : v1
114+ kind : ServiceAccount
115+ metadata :
116+ name : imperative-admin-sa
117+ namespace : imperative
118+ ---
112119# Source: clustergroup/templates/imperative/configmap.yaml
113120apiVersion : v1
114121kind : ConfigMap
@@ -237,6 +244,9 @@ data:
237244 initContainers: []
238245 imperative:
239246 activeDeadlineSeconds: 3600
247+ adminClusterRoleName: imperative-admin-cluster-role
248+ adminServiceAccountCreate: true
249+ adminServiceAccountName: imperative-admin-sa
240250 clusterRoleName: imperative-cluster-role
241251 clusterRoleYaml: ""
242252 cronJobName: imperative-cronjob
@@ -425,11 +435,24 @@ rules:
425435 - list
426436 - watch
427437---
438+ # Source: clustergroup/templates/imperative/clusterrole.yaml
439+ apiVersion : rbac.authorization.k8s.io/v1
440+ kind : ClusterRole
441+ metadata :
442+ name : imperative-admin-cluster-role
443+ rules :
444+ - apiGroups :
445+ - ' *'
446+ resources :
447+ - ' *'
448+ verbs :
449+ - ' *'
450+ ---
428451# Source: clustergroup/templates/imperative/rbac.yaml
429452apiVersion : rbac.authorization.k8s.io/v1
430453kind : ClusterRoleBinding
431454metadata :
432- name : imperative-cluster-admin- rolebinding
455+ name : imperative-cluster-rolebinding
433456roleRef :
434457 apiGroup : rbac.authorization.k8s.io
435458 kind : ClusterRole
@@ -439,6 +462,20 @@ subjects:
439462 name : imperative-sa
440463 namespace : imperative
441464---
465+ # Source: clustergroup/templates/imperative/rbac.yaml
466+ apiVersion : rbac.authorization.k8s.io/v1
467+ kind : ClusterRoleBinding
468+ metadata :
469+ name : imperative-admin-clusterrolebinding
470+ roleRef :
471+ apiGroup : rbac.authorization.k8s.io
472+ kind : ClusterRole
473+ name : imperative-admin-cluster-role
474+ subjects :
475+ - kind : ServiceAccount
476+ name : imperative-admin-sa
477+ namespace : imperative
478+ ---
442479# Source: clustergroup/templates/plumbing/argocd-super-role.yaml
443480# WARNING: ONLY USE THIS FOR MANAGING CLUSTERS NOT FOR REGULAR USERS
444481apiVersion : rbac.authorization.k8s.io/v1
@@ -501,7 +538,7 @@ rules:
501538apiVersion : rbac.authorization.k8s.io/v1
502539kind : RoleBinding
503540metadata :
504- name : imperative-admin- rolebinding
541+ name : imperative-rolebinding
505542 namespace : imperative
506543roleRef :
507544 apiGroup : rbac.authorization.k8s.io
0 commit comments