zoukankan      html  css  js  c++  java
  • kubernetes RBAC

    Role:

    kind: Role

    apiVersion: rbac.authorization.k8s.io/v1

    metadata:

      namespace: gauss

      name: gauss-op

    rules:

    - apiGroups: ["*"]

      resources: ["*"]

      verbs: ["*"]

    RoleBinding:

    kind: RoleBinding

    apiVersion: rbac.authorization.k8s.io/v1

    metadata:

      name: bach-gauss-rb

      namespace: gauss

    subjects:

    - kind: ServiceAccount

      name: bach-gauss

    roleRef:

      kind: Role

      name: gauss-op

      apiGroup: rbac.authorization.k8s.io

    ClusterRole:

    apiVersion: rbac.authorization.k8s.io/v1alpha1

    kind: ClusterRole

    metadata:

      name: cluster-read-all

    rules:

      -

        apiGroups:

          - ""

          - apps

          - autoscaling

          - batch

          - extensions

          - policy

          - rbac.authorization.k8s.io

        resources:

          - componentstatuses

          - configmaps

          - daemonsets

          - deployments

          - events

          - endpoints

          - horizontalpodautoscalers

          - ingress

          - jobs

          - limitranges

          - namespaces

          - nodes

          - pods

          - persistentvolumes

          - persistentvolumeclaims

          - resourcequotas

          - replicasets

          - replicationcontrollers

          - serviceaccounts

          - services

          - secrets

          - ingresses

          - statefulsets

        verbs:

          - get

          - watch

          - list

      - nonResourceURLs: ["*"]

        verbs:

          - get

          - watch

          - list

    ClusterRoleBinding

    kind: ClusterRoleBinding

    apiVersion: rbac.authorization.k8s.io/v1beta1

    metadata:

      name: read-secrets-global

    subjects:

    - kind: ServiceAccount

      name: kubernetes-dashboard

      namespace: kube-system

    roleRef:

      kind: ClusterRole

      name: cluster-read-all

      apiGroup: rbac.authorization.k8s.io

  • 相关阅读:
    [转]怎么看工作是否到位
    [转]一个合格程序员该做的事情——你做好了吗?
    深入图解虚拟机(一)--一个问题引出的思考
    正则表达式边用边学(一)——分组、捕获
    redhat无法注册RHN的解决办法
    使用jquery扩展表格行合并方法探究
    扩展jquery easyui datagrid编辑单元格
    js点滴知识(1) -- 获取DOM对象和编码
    使用雅虎YUI Compressor压缩JS过程心得记录
    插曲一--记《数据结构与问题求解(Java语言版)(第4版)》翻译问题
  • 原文地址:https://www.cnblogs.com/allenhaozi/p/8659559.html
Copyright © 2011-2022 走看看