| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182 |
- apiVersion: v1
- items:
- - apiVersion: rbac.authorization.k8s.io/v1
- kind: Role
- metadata:
- annotations:
- rbac.authorization.kubernetes.io/autoupdate: "true"
- creationTimestamp: null
- labels:
- kubernetes.io/bootstrapping: rbac-defaults
- name: system:controller:bootstrap-signer
- namespace: kube-public
- rules:
- - apiGroups:
- - ""
- resources:
- - configmaps
- verbs:
- - get
- - list
- - watch
- - apiGroups:
- - ""
- resourceNames:
- - cluster-info
- resources:
- - configmaps
- verbs:
- - update
- - apiGroups:
- - ""
- - events.k8s.io
- resources:
- - events
- verbs:
- - create
- - patch
- - update
- - apiVersion: rbac.authorization.k8s.io/v1
- kind: Role
- metadata:
- annotations:
- rbac.authorization.kubernetes.io/autoupdate: "true"
- creationTimestamp: null
- labels:
- kubernetes.io/bootstrapping: rbac-defaults
- name: extension-apiserver-authentication-reader
- namespace: kube-system
- rules:
- - apiGroups:
- - ""
- resourceNames:
- - extension-apiserver-authentication
- resources:
- - configmaps
- verbs:
- - get
- - list
- - watch
- - apiVersion: rbac.authorization.k8s.io/v1
- kind: Role
- metadata:
- annotations:
- rbac.authorization.kubernetes.io/autoupdate: "true"
- creationTimestamp: null
- labels:
- kubernetes.io/bootstrapping: rbac-defaults
- name: system::leader-locking-kube-controller-manager
- namespace: kube-system
- rules:
- - apiGroups:
- - ""
- resources:
- - configmaps
- verbs:
- - watch
- - apiGroups:
- - ""
- resourceNames:
- - kube-controller-manager
- resources:
- - configmaps
- verbs:
- - get
- - update
- - apiVersion: rbac.authorization.k8s.io/v1
- kind: Role
- metadata:
- annotations:
- rbac.authorization.kubernetes.io/autoupdate: "true"
- creationTimestamp: null
- labels:
- kubernetes.io/bootstrapping: rbac-defaults
- name: system::leader-locking-kube-scheduler
- namespace: kube-system
- rules:
- - apiGroups:
- - ""
- resources:
- - configmaps
- verbs:
- - watch
- - apiGroups:
- - ""
- resourceNames:
- - kube-scheduler
- resources:
- - configmaps
- verbs:
- - get
- - update
- - apiVersion: rbac.authorization.k8s.io/v1
- kind: Role
- metadata:
- annotations:
- rbac.authorization.kubernetes.io/autoupdate: "true"
- creationTimestamp: null
- labels:
- kubernetes.io/bootstrapping: rbac-defaults
- name: system:controller:bootstrap-signer
- namespace: kube-system
- rules:
- - apiGroups:
- - ""
- resources:
- - secrets
- verbs:
- - get
- - list
- - watch
- - apiVersion: rbac.authorization.k8s.io/v1
- kind: Role
- metadata:
- annotations:
- rbac.authorization.kubernetes.io/autoupdate: "true"
- creationTimestamp: null
- labels:
- kubernetes.io/bootstrapping: rbac-defaults
- name: system:controller:cloud-provider
- namespace: kube-system
- rules:
- - apiGroups:
- - ""
- resources:
- - configmaps
- verbs:
- - create
- - get
- - list
- - watch
- - apiVersion: rbac.authorization.k8s.io/v1
- kind: Role
- metadata:
- annotations:
- rbac.authorization.kubernetes.io/autoupdate: "true"
- creationTimestamp: null
- labels:
- kubernetes.io/bootstrapping: rbac-defaults
- name: system:controller:token-cleaner
- namespace: kube-system
- rules:
- - apiGroups:
- - ""
- resources:
- - secrets
- verbs:
- - delete
- - get
- - list
- - watch
- - apiGroups:
- - ""
- - events.k8s.io
- resources:
- - events
- verbs:
- - create
- - patch
- - update
- kind: List
- metadata: {}
|