namespace-roles.yaml 3.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182
  1. apiVersion: v1
  2. items:
  3. - apiVersion: rbac.authorization.k8s.io/v1
  4. kind: Role
  5. metadata:
  6. annotations:
  7. rbac.authorization.kubernetes.io/autoupdate: "true"
  8. creationTimestamp: null
  9. labels:
  10. kubernetes.io/bootstrapping: rbac-defaults
  11. name: system:controller:bootstrap-signer
  12. namespace: kube-public
  13. rules:
  14. - apiGroups:
  15. - ""
  16. resources:
  17. - configmaps
  18. verbs:
  19. - get
  20. - list
  21. - watch
  22. - apiGroups:
  23. - ""
  24. resourceNames:
  25. - cluster-info
  26. resources:
  27. - configmaps
  28. verbs:
  29. - update
  30. - apiGroups:
  31. - ""
  32. - events.k8s.io
  33. resources:
  34. - events
  35. verbs:
  36. - create
  37. - patch
  38. - update
  39. - apiVersion: rbac.authorization.k8s.io/v1
  40. kind: Role
  41. metadata:
  42. annotations:
  43. rbac.authorization.kubernetes.io/autoupdate: "true"
  44. creationTimestamp: null
  45. labels:
  46. kubernetes.io/bootstrapping: rbac-defaults
  47. name: extension-apiserver-authentication-reader
  48. namespace: kube-system
  49. rules:
  50. - apiGroups:
  51. - ""
  52. resourceNames:
  53. - extension-apiserver-authentication
  54. resources:
  55. - configmaps
  56. verbs:
  57. - get
  58. - list
  59. - watch
  60. - apiVersion: rbac.authorization.k8s.io/v1
  61. kind: Role
  62. metadata:
  63. annotations:
  64. rbac.authorization.kubernetes.io/autoupdate: "true"
  65. creationTimestamp: null
  66. labels:
  67. kubernetes.io/bootstrapping: rbac-defaults
  68. name: system::leader-locking-kube-controller-manager
  69. namespace: kube-system
  70. rules:
  71. - apiGroups:
  72. - ""
  73. resources:
  74. - configmaps
  75. verbs:
  76. - watch
  77. - apiGroups:
  78. - ""
  79. resourceNames:
  80. - kube-controller-manager
  81. resources:
  82. - configmaps
  83. verbs:
  84. - get
  85. - update
  86. - apiVersion: rbac.authorization.k8s.io/v1
  87. kind: Role
  88. metadata:
  89. annotations:
  90. rbac.authorization.kubernetes.io/autoupdate: "true"
  91. creationTimestamp: null
  92. labels:
  93. kubernetes.io/bootstrapping: rbac-defaults
  94. name: system::leader-locking-kube-scheduler
  95. namespace: kube-system
  96. rules:
  97. - apiGroups:
  98. - ""
  99. resources:
  100. - configmaps
  101. verbs:
  102. - watch
  103. - apiGroups:
  104. - ""
  105. resourceNames:
  106. - kube-scheduler
  107. resources:
  108. - configmaps
  109. verbs:
  110. - get
  111. - update
  112. - apiVersion: rbac.authorization.k8s.io/v1
  113. kind: Role
  114. metadata:
  115. annotations:
  116. rbac.authorization.kubernetes.io/autoupdate: "true"
  117. creationTimestamp: null
  118. labels:
  119. kubernetes.io/bootstrapping: rbac-defaults
  120. name: system:controller:bootstrap-signer
  121. namespace: kube-system
  122. rules:
  123. - apiGroups:
  124. - ""
  125. resources:
  126. - secrets
  127. verbs:
  128. - get
  129. - list
  130. - watch
  131. - apiVersion: rbac.authorization.k8s.io/v1
  132. kind: Role
  133. metadata:
  134. annotations:
  135. rbac.authorization.kubernetes.io/autoupdate: "true"
  136. creationTimestamp: null
  137. labels:
  138. kubernetes.io/bootstrapping: rbac-defaults
  139. name: system:controller:cloud-provider
  140. namespace: kube-system
  141. rules:
  142. - apiGroups:
  143. - ""
  144. resources:
  145. - configmaps
  146. verbs:
  147. - create
  148. - get
  149. - list
  150. - watch
  151. - apiVersion: rbac.authorization.k8s.io/v1
  152. kind: Role
  153. metadata:
  154. annotations:
  155. rbac.authorization.kubernetes.io/autoupdate: "true"
  156. creationTimestamp: null
  157. labels:
  158. kubernetes.io/bootstrapping: rbac-defaults
  159. name: system:controller:token-cleaner
  160. namespace: kube-system
  161. rules:
  162. - apiGroups:
  163. - ""
  164. resources:
  165. - secrets
  166. verbs:
  167. - delete
  168. - get
  169. - list
  170. - watch
  171. - apiGroups:
  172. - ""
  173. - events.k8s.io
  174. resources:
  175. - events
  176. verbs:
  177. - create
  178. - patch
  179. - update
  180. kind: List
  181. metadata: {}