{{- if and .Values.create.enabled (eq .Values.create.appRole.mode "k8s") -}} apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: {{ include "vault.fullname" . }}-binding subjects: - kind: ServiceAccount name: {{ include "vault.fullname" . }}-sa roleRef: kind: Role name: {{ include "vault.fullname" . }}-role apiGroup: rbac.authorization.k8s.io {{- end -}}