{{- if .Values.serviceAccount.create }} {{/* One ServiceAccount per service, not one shared. The api talks only to Postgres and has no Kubernetes rights at all; giving it the worker's identity would hand an internet-facing HTTP surface the ability to create namespaces. */}} {{- range $component := list "api" "worker" "reconciler" }} --- apiVersion: v1 kind: ServiceAccount metadata: name: {{ include "svcforge.serviceAccountName" (dict "ctx" $ "component" $component) }} labels: {{- include "svcforge.labels" $ | nindent 4 }} app.kubernetes.io/component: {{ $component }} {{- with $.Values.serviceAccount.annotations }} annotations: {{- toYaml . | nindent 4 }} {{- end }} # The api never calls the API server, so it gets no token. The worker and reconciler both # shell out to helm, which needs one. automountServiceAccountToken: {{ ne $component "api" }} {{- end }} {{- end }}