You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

64 lines
902 B

  1. ---
  2. kind: ClusterRole
  3. apiVersion: rbac.authorization.k8s.io/v1beta1
  4. metadata:
  5. name: cilium
  6. rules:
  7. - apiGroups:
  8. - "networking.k8s.io"
  9. resources:
  10. - networkpolicies
  11. verbs:
  12. - get
  13. - list
  14. - watch
  15. - apiGroups:
  16. - ""
  17. resources:
  18. - namespaces
  19. - services
  20. - nodes
  21. - endpoints
  22. - componentstatuses
  23. verbs:
  24. - get
  25. - list
  26. - watch
  27. - apiGroups:
  28. - ""
  29. resources:
  30. - pods
  31. - nodes
  32. verbs:
  33. - get
  34. - list
  35. - watch
  36. - update
  37. - apiGroups:
  38. - extensions
  39. resources:
  40. - networkpolicies #FIXME remove this when we drop support for k8s NP-beta GH-1202
  41. - thirdpartyresources
  42. - ingresses
  43. verbs:
  44. - create
  45. - get
  46. - list
  47. - watch
  48. - apiGroups:
  49. - "apiextensions.k8s.io"
  50. resources:
  51. - customresourcedefinitions
  52. verbs:
  53. - create
  54. - get
  55. - list
  56. - watch
  57. - update
  58. - apiGroups:
  59. - cilium.io
  60. resources:
  61. - ciliumnetworkpolicies
  62. - ciliumendpoints
  63. verbs:
  64. - "*"