kubeasz/manifests/dashboard/read-user-sa-rbac.yaml

166 lines
2.5 KiB
YAML
Raw Normal View History

2018-11-27 09:14:05 +08:00
apiVersion: v1
kind: ServiceAccount
metadata:
name: dashboard-read-user
namespace: kube-system
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: dashboard-read-binding
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: dashboard-read-clusterrole
subjects:
- kind: ServiceAccount
name: dashboard-read-user
namespace: kube-system
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: dashboard-read-clusterrole
rules:
- apiGroups:
- ""
resources:
- configmaps
- endpoints
2019-10-27 21:40:43 +08:00
- nodes
- persistentvolumes
2018-11-27 09:14:05 +08:00
- persistentvolumeclaims
2019-10-27 21:40:43 +08:00
- persistentvolumeclaims/status
2018-11-27 09:14:05 +08:00
- pods
- replicationcontrollers
- replicationcontrollers/scale
- serviceaccounts
- services
2019-10-27 21:40:43 +08:00
- services/status
2018-11-27 09:14:05 +08:00
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- bindings
- events
- limitranges
- namespaces/status
- pods/log
- pods/status
- replicationcontrollers/status
- resourcequotas
- resourcequotas/status
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- namespaces
verbs:
- get
- list
- watch
- apiGroups:
- apps
resources:
2019-10-27 21:40:43 +08:00
- controllerrevisions
2018-11-27 09:14:05 +08:00
- daemonsets
2019-10-27 21:40:43 +08:00
- daemonsets/status
2018-11-27 09:14:05 +08:00
- deployments
- deployments/scale
2019-10-27 21:40:43 +08:00
- deployments/status
2018-11-27 09:14:05 +08:00
- replicasets
- replicasets/scale
2019-10-27 21:40:43 +08:00
- replicasets/status
2018-11-27 09:14:05 +08:00
- statefulsets
2019-10-27 21:40:43 +08:00
- statefulsets/scale
- statefulsets/status
2018-11-27 09:14:05 +08:00
verbs:
- get
- list
- watch
- apiGroups:
- autoscaling
resources:
- horizontalpodautoscalers
2019-10-27 21:40:43 +08:00
- horizontalpodautoscalers/status
2018-11-27 09:14:05 +08:00
verbs:
- get
- list
- watch
- apiGroups:
- batch
resources:
- cronjobs
2019-10-27 21:40:43 +08:00
- cronjobs/status
2018-11-27 09:14:05 +08:00
- jobs
2019-10-27 21:40:43 +08:00
- jobs/status
2018-11-27 09:14:05 +08:00
verbs:
- get
- list
- watch
- apiGroups:
- extensions
resources:
- daemonsets
2019-10-27 21:40:43 +08:00
- daemonsets/status
2018-11-27 09:14:05 +08:00
- deployments
- deployments/scale
2019-10-27 21:40:43 +08:00
- deployments/status
2018-11-27 09:14:05 +08:00
- ingresses
2019-10-27 21:40:43 +08:00
- ingresses/status
2018-11-27 09:14:05 +08:00
- replicasets
- replicasets/scale
2019-10-27 21:40:43 +08:00
- replicasets/status
2018-11-27 09:14:05 +08:00
- replicationcontrollers/scale
verbs:
- get
- list
- watch
- apiGroups:
- policy
resources:
- poddisruptionbudgets
2019-10-27 21:40:43 +08:00
- poddisruptionbudgets/status
2018-11-27 09:14:05 +08:00
verbs:
- get
- list
- watch
- apiGroups:
- networking.k8s.io
resources:
2019-10-27 21:40:43 +08:00
- ingresses
- ingresses/status
2018-11-27 09:14:05 +08:00
- networkpolicies
verbs:
- get
- list
- watch
- apiGroups:
- storage.k8s.io
resources:
- storageclasses
- volumeattachments
verbs:
- get
- list
- watch
- apiGroups:
- rbac.authorization.k8s.io
resources:
- clusterrolebindings
- clusterroles
- roles
- rolebindings
verbs:
- get
- list
- watch