rbac bootstrap policy: add selfsubjectrulesreviews to basic-user

This commit is contained in:
Eric Chiang
2017-11-20 14:03:04 -08:00
parent db4134d03f
commit 21ab4d0c9b
2 changed files with 2 additions and 1 deletions

View File

@@ -169,7 +169,7 @@ func ClusterRoles() []rbac.ClusterRole {
ObjectMeta: metav1.ObjectMeta{Name: "system:basic-user"}, ObjectMeta: metav1.ObjectMeta{Name: "system:basic-user"},
Rules: []rbac.PolicyRule{ Rules: []rbac.PolicyRule{
// TODO add future selfsubjectrulesreview, project request APIs, project listing APIs // TODO add future selfsubjectrulesreview, project request APIs, project listing APIs
rbac.NewRule("create").Groups(authorizationGroup).Resources("selfsubjectaccessreviews").RuleOrDie(), rbac.NewRule("create").Groups(authorizationGroup).Resources("selfsubjectaccessreviews", "selfsubjectrulesreviews").RuleOrDie(),
}, },
}, },

View File

@@ -522,6 +522,7 @@ items:
- authorization.k8s.io - authorization.k8s.io
resources: resources:
- selfsubjectaccessreviews - selfsubjectaccessreviews
- selfsubjectrulesreviews
verbs: verbs:
- create - create
- apiVersion: rbac.authorization.k8s.io/v1 - apiVersion: rbac.authorization.k8s.io/v1