Update addon manifests to use policy/v1beta1 and grant permissions in policy API group.

This commit is contained in:
Slava Semushin 2018-04-17 12:31:15 +02:00
parent 7966265a51
commit 044bf2e415
12 changed files with 12 additions and 12 deletions

View File

@ -8,7 +8,7 @@ metadata:
addonmanager.kubernetes.io/mode: Reconcile addonmanager.kubernetes.io/mode: Reconcile
rules: rules:
- apiGroups: - apiGroups:
- extensions - policy
resourceNames: resourceNames:
- gce.etcd-empty-dir-cleanup - gce.etcd-empty-dir-cleanup
resources: resources:

View File

@ -1,4 +1,4 @@
apiVersion: extensions/v1beta1 apiVersion: policy/v1beta1
kind: PodSecurityPolicy kind: PodSecurityPolicy
metadata: metadata:
name: gce.etcd-empty-dir-cleanup name: gce.etcd-empty-dir-cleanup

View File

@ -8,7 +8,7 @@ metadata:
addonmanager.kubernetes.io/mode: Reconcile addonmanager.kubernetes.io/mode: Reconcile
rules: rules:
- apiGroups: - apiGroups:
- extensions - policy
resourceNames: resourceNames:
- gce.event-exporter - gce.event-exporter
resources: resources:

View File

@ -1,4 +1,4 @@
apiVersion: extensions/v1beta1 apiVersion: policy/v1beta1
kind: PodSecurityPolicy kind: PodSecurityPolicy
metadata: metadata:
name: gce.event-exporter name: gce.event-exporter

View File

@ -8,7 +8,7 @@ metadata:
addonmanager.kubernetes.io/mode: Reconcile addonmanager.kubernetes.io/mode: Reconcile
rules: rules:
- apiGroups: - apiGroups:
- extensions - policy
resourceNames: resourceNames:
- gce.fluentd-gcp - gce.fluentd-gcp
resources: resources:

View File

@ -1,4 +1,4 @@
apiVersion: extensions/v1beta1 apiVersion: policy/v1beta1
kind: PodSecurityPolicy kind: PodSecurityPolicy
metadata: metadata:
name: gce.fluentd-gcp name: gce.fluentd-gcp

View File

@ -11,7 +11,7 @@ metadata:
addonmanager.kubernetes.io/mode: Reconcile addonmanager.kubernetes.io/mode: Reconcile
rules: rules:
- apiGroups: - apiGroups:
- extensions - policy
resourceNames: resourceNames:
- gce.persistent-volume-binder - gce.persistent-volume-binder
resources: resources:

View File

@ -1,4 +1,4 @@
apiVersion: extensions/v1beta1 apiVersion: policy/v1beta1
kind: PodSecurityPolicy kind: PodSecurityPolicy
metadata: metadata:
name: gce.persistent-volume-binder name: gce.persistent-volume-binder

View File

@ -7,7 +7,7 @@ metadata:
addonmanager.kubernetes.io/mode: Reconcile addonmanager.kubernetes.io/mode: Reconcile
rules: rules:
- apiGroups: - apiGroups:
- extensions - policy
resourceNames: resourceNames:
- gce.privileged - gce.privileged
resources: resources:

View File

@ -1,4 +1,4 @@
apiVersion: extensions/v1beta1 apiVersion: policy/v1beta1
kind: PodSecurityPolicy kind: PodSecurityPolicy
metadata: metadata:
name: gce.privileged name: gce.privileged

View File

@ -8,7 +8,7 @@ metadata:
addonmanager.kubernetes.io/mode: Reconcile addonmanager.kubernetes.io/mode: Reconcile
rules: rules:
- apiGroups: - apiGroups:
- extensions - policy
resourceNames: resourceNames:
- gce.unprivileged-addon - gce.unprivileged-addon
resources: resources:

View File

@ -1,4 +1,4 @@
apiVersion: extensions/v1beta1 apiVersion: policy/v1beta1
kind: PodSecurityPolicy kind: PodSecurityPolicy
metadata: metadata:
name: gce.unprivileged-addon name: gce.unprivileged-addon