PageSourceSearch

https://helm.sh/assets/js/3bb5db0d.fba0b511.js

js helm.sh collected 2026-09-24 07:27:40 UTC 5,677 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkhelm_www=self.webpackChunkhelm_www||[]).push([["35226"],{59132(e,t,s){s.r(t),s.d(t,{metadata:()=>c,default:()=>u,frontMatter:()=>a,contentTitle:()=>i,toc:()=>l,assets:()=>o});var c=JSON.parse('{"id":"chart_best_practices/rbac","title":"Role-Based Access Control","description":"This part of the Best Practices Guide discusses the creation and formatting of RBAC resources in chart manifests.","source":"@site/versioned_docs/version-2/chart_best_practices/rbac.md","sourceDirName":"chart_best_practices","slug":"/chart_best_practices/rbac","permalink":"/docs/v2/chart_best_practices/rbac","draft":false,"unlisted":false,"editUrl":"https://github.com/helm/helm-www/blob/main/versioned_docs/version-2/chart_best_practices/rbac.md","tags":[],"version":"2","sidebarPosition":8,"frontMatter":{"sidebar_position":8,"sidebar_label":"RBAC"},"sidebar":"tutorialSidebar","previous":{"title":"Custom Resource Definitions","permalink":"/docs/v2/chart_best_practices/custom_resource_definitions"},"next":{"title":"Related Projects","permalink":"/docs/v2/related"}}'),n=s(74848),r=s(28453);let a={sidebar_position:8,sidebar_label:"RBAC"},i="Role-Based Access Control",o={},l=[{value:"YAML Configuration",id:"yaml-configuration",level:2},{value:"RBAC Resources Should be Created by Default",id:"rbac-resources-should-be-created-by-default",level:2},{value:"Using RBAC Resources",id:"using-rbac-resources",level:2}];function d(e){let t={code:"code",h1:"h1",h2:"h2",header:"header",li:"li",p:"p",pre:"pre",ul:"ul",...(0,r.R)(),...e.components};return(0,n.jsxs)(n.Fragment,{children:[(0,n.jsx)(t.header,{children:(0,n.jsx)(t.h1,{id:"role-based-access-control",children:"Role-Based Access Control"})}),"\n",(0,n.jsx)(t.p,{children:"This part of the Best Practices Guide discusses the creation and formatting of RBAC resources in chart manifests."}),"\n",(0,n.jsx)(t.p,{children:"RBAC resources are:"}),"\n",(0,n.jsxs)(t.ul,{children:["\n",(0,n.jsx)(t.li,{children:"ServiceAccount (namespaced)"}),"\n",(0,n.jsx)(t.li,{children:"Role (namespaced)"}),"\n",(0,n.jsx)(t.li,{children:"ClusterRole"}),"\n",(0,n.jsx)(t.li,{children:"RoleBinding (namespaced)"}),"\n",(0,n.jsx)(t.li,{children:"ClusterRoleBinding"}),"\n"]}),"\n",(0,n.jsx)(t.h2,{id:"yaml-configuration",children:"YAML Configuration"}),"\n",(0,n.jsx)(t.p,{children:"RBAC and ServiceAccount configuration should happen under separate keys. They are separate things. Splitting these two concepts out in the YAML disambiguates them and make this clearer."}),"\n",(0,n.jsx)(t.pre,{children:(0,n.jsx)(t.code,{className:"language-yaml",children:"rbac:\n  # Specifies whether RBAC resources should be created\n  create: true\n\nserviceAccount:\n  # Specifies whether a ServiceAccount should be created\n  create: true\n  # The name of the ServiceAccount to use.\n  # If not set and create is true, a name is generated using the fullname template\n  name:\n"})}),"\n",(0,n.jsx)(t.p,{children:"This structure can be extended for more complex charts that require multiple ServiceAccounts."}),"\n",(0,n.jsx)(t.pre,{children:(0,n.jsx)(t.code,{className:"language-yaml",children:"serviceAccounts:\n  client:\n    create: true\n    name:\n  server: \n    create: true\n    name:\n"})}),"\n",(0,n.jsx)(t.h2,{id:"rbac-resources-should-be-created-by-default",children:"RBAC Resources Should be Created by Default"}),"\n",(0,n.jsxs)(t.p,{children:[(0,n.jsx)(t.code,{children:"rbac.create"})," should be a boolean value controlling whether RBAC resources are created.  The default should be ",(0,n.jsx)(t.code,{children:"true"}),".  Users who wish to manage RBAC access controls themselves can set this value to ",(0,n.jsx)(t.code,{children:"false"})," (in which case see below)."]}),"\n",(0,n.jsx)(t.h2,{id:"using-rbac-resources",children:"Using RBAC Resources"}),"\n",(0,n.jsxs)(t.p,{children:[(0,n.jsx)(t.code,{children:"serviceAccount.name"})," should set to the name of the ServiceAccount to be used by access-controlled resources created by the chart.  If ",(0,n.jsx)(t.code,{children:"serviceAccount.create"})," is true, then a ServiceAccount with this name should be created.  If the name is not set, then a name is generated using the ",(0,n.jsx)(t.code,{children:"fullname"})," template, If ",(0,n.jsx)(t.code,{children:"serviceAccount.create"})," is false, then it should not be created, but it should still be associated with the same resources so that manually-created RBAC resources created later that reference it will function correctly.  If ",(0,n.jsx)(t.code,{children:"serviceAccount.create"})," is false and the name is not specified, then the default ServiceAccount is used."]}),"\n",(0,n.jsx)(t.p,{children:"The following helper template should be used for the ServiceAccount."}),"\n",(0,n.jsx)(t.pre,{children:(0,n.jsx)(t.code,{className:"language-yaml",children:'{{/*\nCreate the name of the service account to use\n*/}}\n{{- define "mychart.serviceAccountName" -}}\n{{- if .Values.serviceAccount.create -}}\n    {{ default (include "mychart.fullname" .) .Values.serviceAccount.name }}\n{{- else -}}\n    {{ default "default" .Values.serviceAccount.name }}\n{{- end -}}\n{{- end -}}\n'})})]})}function u(e={}){let{wrapper:t}={...(0,r.R)(),...e.components};return t?(0,n.jsx)(t,{...e,children:(0,n.jsx)(d,{...e})}):d(e)}},28453(e,t,s){s.d(t,{R:()=>a,x:()=>i});var c=s(96540);let n={},r=c.createContext(n);function a(e){let t=c.useContext(r);return c.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function i(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(n):e.components||n:a(e.components),c.createElement(r.Provider,{value:t},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.