kubelet-binding.yaml 866 B

1234567891011121314151617181920212223242526272829303132
  1. # This is required so that old clusters don't remove required bindings for 1.5
  2. # kubelets to function.
  3. apiVersion: rbac.authorization.k8s.io/v1
  4. kind: ClusterRoleBinding
  5. metadata:
  6. name: kubelet-cluster-admin
  7. labels:
  8. kubernetes.io/cluster-service: "true"
  9. addonmanager.kubernetes.io/mode: EnsureExists
  10. roleRef:
  11. apiGroup: rbac.authorization.k8s.io
  12. kind: ClusterRole
  13. name: system:node
  14. subjects: []
  15. ---
  16. # This is required so that new clusters still have bootstrap permissions
  17. apiVersion: rbac.authorization.k8s.io/v1
  18. kind: ClusterRoleBinding
  19. metadata:
  20. name: kubelet-bootstrap
  21. labels:
  22. kubernetes.io/cluster-service: "true"
  23. addonmanager.kubernetes.io/mode: Reconcile
  24. roleRef:
  25. apiGroup: rbac.authorization.k8s.io
  26. kind: ClusterRole
  27. name: system:node-bootstrapper
  28. subjects:
  29. - apiGroup: rbac.authorization.k8s.io
  30. kind: User
  31. name: kubelet