kubeadm: fix uninvalid namespace field for clusterrole

Signed-off-by: xin.li <xin.li@daocloud.io>
This commit is contained in:
xin.li 2023-10-15 18:46:29 +08:00
parent 8e8ac86cf1
commit 6732c4110f

View File

@ -55,8 +55,7 @@ func AllowBoostrapTokensToGetNodes(client clientset.Interface) error {
if err := apiclient.CreateOrUpdateClusterRole(client, &rbac.ClusterRole{ if err := apiclient.CreateOrUpdateClusterRole(client, &rbac.ClusterRole{
ObjectMeta: metav1.ObjectMeta{ ObjectMeta: metav1.ObjectMeta{
Name: constants.GetNodesClusterRoleName, Name: constants.GetNodesClusterRoleName,
Namespace: metav1.NamespaceSystem,
}, },
Rules: []rbac.PolicyRule{ Rules: []rbac.PolicyRule{
{ {
@ -71,8 +70,7 @@ func AllowBoostrapTokensToGetNodes(client clientset.Interface) error {
return apiclient.CreateOrUpdateClusterRoleBinding(client, &rbac.ClusterRoleBinding{ return apiclient.CreateOrUpdateClusterRoleBinding(client, &rbac.ClusterRoleBinding{
ObjectMeta: metav1.ObjectMeta{ ObjectMeta: metav1.ObjectMeta{
Name: constants.GetNodesClusterRoleName, Name: constants.GetNodesClusterRoleName,
Namespace: metav1.NamespaceSystem,
}, },
RoleRef: rbac.RoleRef{ RoleRef: rbac.RoleRef{
APIGroup: rbac.GroupName, APIGroup: rbac.GroupName,