csi-controller-rbac.yaml 1.7 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879
  1. apiVersion: v1
  2. kind: ServiceAccount
  3. metadata:
  4. name: csi-controller-sa
  5. ---
  6. kind: ClusterRoleBinding
  7. apiVersion: rbac.authorization.k8s.io/v1
  8. metadata:
  9. name: csi-controller-attacher-role
  10. subjects:
  11. - kind: ServiceAccount
  12. name: csi-controller-sa
  13. namespace: default
  14. roleRef:
  15. kind: ClusterRole
  16. name: external-attacher-runner
  17. apiGroup: rbac.authorization.k8s.io
  18. ---
  19. kind: RoleBinding
  20. apiVersion: rbac.authorization.k8s.io/v1
  21. metadata:
  22. name: csi-controller-attacher-role-cfg
  23. namespace: default
  24. subjects:
  25. - kind: ServiceAccount
  26. name: csi-controller-sa
  27. namespace: default
  28. roleRef:
  29. kind: Role
  30. name: external-attacher-cfg
  31. ---
  32. kind: ClusterRoleBinding
  33. apiVersion: rbac.authorization.k8s.io/v1
  34. metadata:
  35. name: csi-controller-provisioner-role
  36. subjects:
  37. - kind: ServiceAccount
  38. name: csi-controller-sa
  39. namespace: default
  40. roleRef:
  41. kind: ClusterRole
  42. name: external-provisioner-runner
  43. apiGroup: rbac.authorization.k8s.io
  44. ---
  45. kind: RoleBinding
  46. apiVersion: rbac.authorization.k8s.io/v1
  47. metadata:
  48. name: csi-controller-provisioner-role-cfg
  49. namespace: default
  50. subjects:
  51. - kind: ServiceAccount
  52. name: csi-controller-sa
  53. namespace: default
  54. roleRef:
  55. kind: Role
  56. name: external-provisioner-cfg
  57. ---
  58. # priviledged Pod Security Policy, previously defined via PrivilegedTestPSPClusterRoleBinding()
  59. kind: ClusterRoleBinding
  60. apiVersion: rbac.authorization.k8s.io/v1
  61. metadata:
  62. name: psp-csi-controller-driver-registrar-role
  63. subjects:
  64. - kind: ServiceAccount
  65. name: csi-controller-sa
  66. namespace: default
  67. - kind: ServiceAccount
  68. name: csi-node-sa
  69. namespace: default
  70. roleRef:
  71. kind: ClusterRole
  72. name: e2e-test-privileged-psp
  73. apiGroup: rbac.authorization.k8s.io