Update to latest csi/external-provisioner rbac

This commit is contained in:
Matthew Wong 2019-04-05 11:09:25 -04:00
parent 5d9330aa75
commit c802f81045

View File

@ -21,12 +21,14 @@ apiVersion: rbac.authorization.k8s.io/v1
metadata: metadata:
name: external-provisioner-runner name: external-provisioner-runner
rules: rules:
- apiGroups: [""] # The following rule should be uncommented for plugins that require secrets
resources: ["secrets"] # for provisioning.
verbs: ["get", "list"] # - apiGroups: [""]
# resources: ["secrets"]
# verbs: ["get", "list"]
- apiGroups: [""] - apiGroups: [""]
resources: ["persistentvolumes"] resources: ["persistentvolumes"]
verbs: ["get", "list", "watch", "create", "delete"] verbs: ["get", "list", "watch", "update", "create", "delete"]
- apiGroups: [""] - apiGroups: [""]
resources: ["persistentvolumeclaims"] resources: ["persistentvolumeclaims"]
verbs: ["get", "list", "watch", "update"] verbs: ["get", "list", "watch", "update"]
@ -74,9 +76,14 @@ metadata:
namespace: default namespace: default
name: external-provisioner-cfg name: external-provisioner-cfg
rules: rules:
# Only one of the following rules for endpoints or leases is required based on
# what is set for `--leader-election-type`. Endpoints are deprecated in favor of Leases.
- apiGroups: [""] - apiGroups: [""]
resources: ["endpoints"] resources: ["endpoints"]
verbs: ["get", "watch", "list", "delete", "update", "create"] verbs: ["get", "watch", "list", "delete", "update", "create"]
- apiGroups: ["coordination.k8s.io"]
resources: ["leases"]
verbs: ["get", "watch", "list", "delete", "update", "create"]
--- ---
kind: RoleBinding kind: RoleBinding