{{- if .Values.api.serviceAccountIssuer }} apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: oidc-public roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: system:service-account-issuer-discovery subjects: - kind: Group name: system:unauthenticated {{- end }}