You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

109 lines
1.5 KiB

  1. apiVersion: v1
  2. items:
  3. - apiVersion: rbac.authorization.k8s.io/v1
  4. kind: ClusterRole
  5. metadata:
  6. name: system:cloud-controller-manager
  7. rules:
  8. - apiGroups:
  9. - coordination.k8s.io
  10. resources:
  11. - leases
  12. verbs:
  13. - get
  14. - create
  15. - update
  16. - apiGroups:
  17. - ""
  18. resources:
  19. - events
  20. verbs:
  21. - create
  22. - patch
  23. - update
  24. - apiGroups:
  25. - ""
  26. resources:
  27. - nodes
  28. verbs:
  29. - '*'
  30. - apiGroups:
  31. - ""
  32. resources:
  33. - nodes/status
  34. verbs:
  35. - patch
  36. - apiGroups:
  37. - ""
  38. resources:
  39. - services
  40. verbs:
  41. - list
  42. - patch
  43. - update
  44. - watch
  45. - apiGroups:
  46. - ""
  47. resources:
  48. - services/status
  49. verbs:
  50. - patch
  51. - apiGroups:
  52. - ""
  53. resources:
  54. - serviceaccounts/token
  55. verbs:
  56. - create
  57. - apiGroups:
  58. - ""
  59. resources:
  60. - serviceaccounts
  61. verbs:
  62. - create
  63. - get
  64. - apiGroups:
  65. - ""
  66. resources:
  67. - persistentvolumes
  68. verbs:
  69. - '*'
  70. - apiGroups:
  71. - ""
  72. resources:
  73. - endpoints
  74. verbs:
  75. - create
  76. - get
  77. - list
  78. - watch
  79. - update
  80. - apiGroups:
  81. - ""
  82. resources:
  83. - configmaps
  84. verbs:
  85. - get
  86. - list
  87. - watch
  88. - apiGroups:
  89. - ""
  90. resources:
  91. - secrets
  92. verbs:
  93. - list
  94. - get
  95. - watch
  96. - apiGroups:
  97. - authentication.k8s.io
  98. resources:
  99. - tokenreviews
  100. verbs:
  101. - create
  102. - apiGroups:
  103. - authorization.k8s.io
  104. resources:
  105. - subjectaccessreviews
  106. verbs:
  107. - create
  108. kind: List
  109. metadata: {}