{{- if index .Values.ocScheduler.enabled }} apiVersion: v1 kind: ServiceAccount metadata: name: scheduler-sa namespace: {{ .Release.Namespace }} --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: scheduler-sa-clusterrole rules: # Permissions for Argo Workflow resources - apiGroups: ["argoproj.io"] resources: - workflows - workflowtemplates - cronworkflows - clusterworkflowtemplates verbs: - create - delete - get - list - patch - update - watch --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: scheduler-sa-clusterrolebinding subjects: - kind: ServiceAccount name: scheduler-sa namespace: {{ .Release.Namespace }} roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: scheduler-sa-clusterrole {{- end }}