{{- if and  .Values.zabbixAgent.rbac.create .Values.zabbixAgent.rbac.pspEnabled -}}
kind: ClusterRole
apiVersion: rbac.authorization.k8s.io/v1
metadata:
  name:  psp-{{ template "zabbix.agent.fullname" . }}
rules:
  - apiGroups: ['extensions']
    resources: ['podsecuritypolicies']
    verbs:     ['use']
    resourceNames:
      - {{ template "zabbix.agent.fullname" . }}
  - apiGroups: ['security.openshift.io']
    verbs:     ['use']
    resources: ['securitycontextconstraints']
    resourceNames:
      - privileged
      - hostaccess
      - hostnetwork
{{- end -}}