{{- if .Values.serviceAccount.create -}} apiVersion: v1 kind: ServiceAccount metadata: name: {{ include "kubectl-mcp-server.serviceAccountName" . }} namespace: {{ .Release.Namespace }} labels: {{- include "kubectl-mcp-server.labels" . | nindent 4 }} {{- with .Values.serviceAccount.annotations }} annotations: {{- toYaml . | nindent 4 }} {{- end }} # Unlike elasticsearch-mcp (which authenticates to ES via ExternalSecret # creds), kubectl-mcp-server authenticates to the API server with this SA's # token via in-cluster config — the token MUST be mounted. automountServiceAccountToken: true {{- end }}