You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

142 lines
2.0 KiB

  1. apiVersion: v1
  2. items:
  3. - apiVersion: rbac.authorization.k8s.io/v1
  4. kind: ClusterRole
  5. metadata:
  6. name: system:cloud-controller-manager
  7. rules:
  8. - apiGroups:
  9. - coordination.k8s.io
  10. resources:
  11. - leases
  12. verbs:
  13. - get
  14. - create
  15. - update
  16. - apiGroups:
  17. - ""
  18. resources:
  19. - events
  20. verbs:
  21. - create
  22. - patch
  23. - update
  24. - apiGroups:
  25. - ""
  26. resources:
  27. - nodes
  28. verbs:
  29. - '*'
  30. - apiGroups:
  31. - ""
  32. resources:
  33. - nodes/status
  34. verbs:
  35. - patch
  36. - apiGroups:
  37. - ""
  38. resources:
  39. - services
  40. verbs:
  41. - list
  42. - patch
  43. - update
  44. - watch
  45. - apiGroups:
  46. - ""
  47. resources:
  48. - serviceaccounts
  49. verbs:
  50. - create
  51. - get
  52. - apiGroups:
  53. - ""
  54. resources:
  55. - persistentvolumes
  56. verbs:
  57. - '*'
  58. - apiGroups:
  59. - ""
  60. resources:
  61. - endpoints
  62. verbs:
  63. - create
  64. - get
  65. - list
  66. - watch
  67. - update
  68. - apiGroups:
  69. - ""
  70. resources:
  71. - configmaps
  72. verbs:
  73. - get
  74. - list
  75. - watch
  76. - apiGroups:
  77. - ""
  78. resources:
  79. - secrets
  80. verbs:
  81. - list
  82. - get
  83. - watch
  84. - apiGroups:
  85. - authentication.k8s.io
  86. resources:
  87. - tokenreviews
  88. verbs:
  89. - create
  90. - apiGroups:
  91. - authorization.k8s.io
  92. resources:
  93. - subjectaccessreviews
  94. verbs:
  95. - create
  96. - apiVersion: rbac.authorization.k8s.io/v1
  97. kind: ClusterRole
  98. metadata:
  99. name: system:cloud-node-controller
  100. rules:
  101. - apiGroups:
  102. - ""
  103. resources:
  104. - nodes
  105. verbs:
  106. - '*'
  107. - apiGroups:
  108. - ""
  109. resources:
  110. - nodes/status
  111. verbs:
  112. - patch
  113. - apiGroups:
  114. - ""
  115. resources:
  116. - events
  117. verbs:
  118. - create
  119. - patch
  120. - update
  121. - apiVersion: rbac.authorization.k8s.io/v1
  122. kind: ClusterRole
  123. metadata:
  124. name: system:pvl-controller
  125. rules:
  126. - apiGroups:
  127. - ""
  128. resources:
  129. - persistentvolumes
  130. verbs:
  131. - '*'
  132. - apiGroups:
  133. - ""
  134. resources:
  135. - events
  136. verbs:
  137. - create
  138. - patch
  139. - update
  140. kind: List
  141. metadata: {}