controller-roles.yaml 21 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254
  1. apiVersion: v1
  2. items:
  3. - apiVersion: rbac.authorization.k8s.io/v1
  4. kind: ClusterRole
  5. metadata:
  6. annotations:
  7. rbac.authorization.kubernetes.io/autoupdate: "true"
  8. creationTimestamp: null
  9. labels:
  10. kubernetes.io/bootstrapping: rbac-defaults
  11. name: system:controller:attachdetach-controller
  12. rules:
  13. - apiGroups:
  14. - ""
  15. resources:
  16. - persistentvolumeclaims
  17. - persistentvolumes
  18. verbs:
  19. - list
  20. - watch
  21. - apiGroups:
  22. - ""
  23. resources:
  24. - nodes
  25. verbs:
  26. - get
  27. - list
  28. - watch
  29. - apiGroups:
  30. - ""
  31. resources:
  32. - nodes/status
  33. verbs:
  34. - patch
  35. - update
  36. - apiGroups:
  37. - ""
  38. resources:
  39. - pods
  40. verbs:
  41. - list
  42. - watch
  43. - apiGroups:
  44. - ""
  45. resources:
  46. - events
  47. verbs:
  48. - create
  49. - patch
  50. - update
  51. - apiGroups:
  52. - storage.k8s.io
  53. resources:
  54. - volumeattachments
  55. verbs:
  56. - create
  57. - delete
  58. - get
  59. - list
  60. - watch
  61. - apiGroups:
  62. - storage.k8s.io
  63. resources:
  64. - csidrivers
  65. verbs:
  66. - get
  67. - list
  68. - watch
  69. - apiVersion: rbac.authorization.k8s.io/v1
  70. kind: ClusterRole
  71. metadata:
  72. annotations:
  73. rbac.authorization.kubernetes.io/autoupdate: "true"
  74. creationTimestamp: null
  75. labels:
  76. kubernetes.io/bootstrapping: rbac-defaults
  77. name: system:controller:certificate-controller
  78. rules:
  79. - apiGroups:
  80. - certificates.k8s.io
  81. resources:
  82. - certificatesigningrequests
  83. verbs:
  84. - delete
  85. - get
  86. - list
  87. - watch
  88. - apiGroups:
  89. - certificates.k8s.io
  90. resources:
  91. - certificatesigningrequests/approval
  92. - certificatesigningrequests/status
  93. verbs:
  94. - update
  95. - apiGroups:
  96. - authorization.k8s.io
  97. resources:
  98. - subjectaccessreviews
  99. verbs:
  100. - create
  101. - apiGroups:
  102. - ""
  103. resources:
  104. - events
  105. verbs:
  106. - create
  107. - patch
  108. - update
  109. - apiVersion: rbac.authorization.k8s.io/v1
  110. kind: ClusterRole
  111. metadata:
  112. annotations:
  113. rbac.authorization.kubernetes.io/autoupdate: "true"
  114. creationTimestamp: null
  115. labels:
  116. kubernetes.io/bootstrapping: rbac-defaults
  117. name: system:controller:clusterrole-aggregation-controller
  118. rules:
  119. - apiGroups:
  120. - '*'
  121. resources:
  122. - '*'
  123. verbs:
  124. - '*'
  125. - nonResourceURLs:
  126. - '*'
  127. verbs:
  128. - '*'
  129. - apiVersion: rbac.authorization.k8s.io/v1
  130. kind: ClusterRole
  131. metadata:
  132. annotations:
  133. rbac.authorization.kubernetes.io/autoupdate: "true"
  134. creationTimestamp: null
  135. labels:
  136. kubernetes.io/bootstrapping: rbac-defaults
  137. name: system:controller:cronjob-controller
  138. rules:
  139. - apiGroups:
  140. - batch
  141. resources:
  142. - cronjobs
  143. verbs:
  144. - get
  145. - list
  146. - update
  147. - watch
  148. - apiGroups:
  149. - batch
  150. resources:
  151. - jobs
  152. verbs:
  153. - create
  154. - delete
  155. - get
  156. - list
  157. - patch
  158. - update
  159. - watch
  160. - apiGroups:
  161. - batch
  162. resources:
  163. - cronjobs/status
  164. verbs:
  165. - update
  166. - apiGroups:
  167. - batch
  168. resources:
  169. - cronjobs/finalizers
  170. verbs:
  171. - update
  172. - apiGroups:
  173. - ""
  174. resources:
  175. - pods
  176. verbs:
  177. - delete
  178. - list
  179. - apiGroups:
  180. - ""
  181. resources:
  182. - events
  183. verbs:
  184. - create
  185. - patch
  186. - update
  187. - apiVersion: rbac.authorization.k8s.io/v1
  188. kind: ClusterRole
  189. metadata:
  190. annotations:
  191. rbac.authorization.kubernetes.io/autoupdate: "true"
  192. creationTimestamp: null
  193. labels:
  194. kubernetes.io/bootstrapping: rbac-defaults
  195. name: system:controller:daemon-set-controller
  196. rules:
  197. - apiGroups:
  198. - apps
  199. - extensions
  200. resources:
  201. - daemonsets
  202. verbs:
  203. - get
  204. - list
  205. - watch
  206. - apiGroups:
  207. - apps
  208. - extensions
  209. resources:
  210. - daemonsets/status
  211. verbs:
  212. - update
  213. - apiGroups:
  214. - apps
  215. - extensions
  216. resources:
  217. - daemonsets/finalizers
  218. verbs:
  219. - update
  220. - apiGroups:
  221. - ""
  222. resources:
  223. - nodes
  224. verbs:
  225. - list
  226. - watch
  227. - apiGroups:
  228. - ""
  229. resources:
  230. - pods
  231. verbs:
  232. - create
  233. - delete
  234. - list
  235. - patch
  236. - watch
  237. - apiGroups:
  238. - ""
  239. resources:
  240. - pods/binding
  241. verbs:
  242. - create
  243. - apiGroups:
  244. - apps
  245. resources:
  246. - controllerrevisions
  247. verbs:
  248. - create
  249. - delete
  250. - get
  251. - list
  252. - patch
  253. - update
  254. - watch
  255. - apiGroups:
  256. - ""
  257. resources:
  258. - events
  259. verbs:
  260. - create
  261. - patch
  262. - update
  263. - apiVersion: rbac.authorization.k8s.io/v1
  264. kind: ClusterRole
  265. metadata:
  266. annotations:
  267. rbac.authorization.kubernetes.io/autoupdate: "true"
  268. creationTimestamp: null
  269. labels:
  270. kubernetes.io/bootstrapping: rbac-defaults
  271. name: system:controller:deployment-controller
  272. rules:
  273. - apiGroups:
  274. - apps
  275. - extensions
  276. resources:
  277. - deployments
  278. verbs:
  279. - get
  280. - list
  281. - update
  282. - watch
  283. - apiGroups:
  284. - apps
  285. - extensions
  286. resources:
  287. - deployments/status
  288. verbs:
  289. - update
  290. - apiGroups:
  291. - apps
  292. - extensions
  293. resources:
  294. - deployments/finalizers
  295. verbs:
  296. - update
  297. - apiGroups:
  298. - apps
  299. - extensions
  300. resources:
  301. - replicasets
  302. verbs:
  303. - create
  304. - delete
  305. - get
  306. - list
  307. - patch
  308. - update
  309. - watch
  310. - apiGroups:
  311. - ""
  312. resources:
  313. - pods
  314. verbs:
  315. - get
  316. - list
  317. - update
  318. - watch
  319. - apiGroups:
  320. - ""
  321. resources:
  322. - events
  323. verbs:
  324. - create
  325. - patch
  326. - update
  327. - apiVersion: rbac.authorization.k8s.io/v1
  328. kind: ClusterRole
  329. metadata:
  330. annotations:
  331. rbac.authorization.kubernetes.io/autoupdate: "true"
  332. creationTimestamp: null
  333. labels:
  334. kubernetes.io/bootstrapping: rbac-defaults
  335. name: system:controller:disruption-controller
  336. rules:
  337. - apiGroups:
  338. - apps
  339. - extensions
  340. resources:
  341. - deployments
  342. verbs:
  343. - get
  344. - list
  345. - watch
  346. - apiGroups:
  347. - apps
  348. - extensions
  349. resources:
  350. - replicasets
  351. verbs:
  352. - get
  353. - list
  354. - watch
  355. - apiGroups:
  356. - ""
  357. resources:
  358. - replicationcontrollers
  359. verbs:
  360. - get
  361. - list
  362. - watch
  363. - apiGroups:
  364. - policy
  365. resources:
  366. - poddisruptionbudgets
  367. verbs:
  368. - get
  369. - list
  370. - watch
  371. - apiGroups:
  372. - apps
  373. resources:
  374. - statefulsets
  375. verbs:
  376. - get
  377. - list
  378. - watch
  379. - apiGroups:
  380. - policy
  381. resources:
  382. - poddisruptionbudgets/status
  383. verbs:
  384. - update
  385. - apiGroups:
  386. - '*'
  387. resources:
  388. - '*/scale'
  389. verbs:
  390. - get
  391. - apiGroups:
  392. - ""
  393. resources:
  394. - events
  395. verbs:
  396. - create
  397. - patch
  398. - update
  399. - apiVersion: rbac.authorization.k8s.io/v1
  400. kind: ClusterRole
  401. metadata:
  402. annotations:
  403. rbac.authorization.kubernetes.io/autoupdate: "true"
  404. creationTimestamp: null
  405. labels:
  406. kubernetes.io/bootstrapping: rbac-defaults
  407. name: system:controller:endpoint-controller
  408. rules:
  409. - apiGroups:
  410. - ""
  411. resources:
  412. - pods
  413. - services
  414. verbs:
  415. - get
  416. - list
  417. - watch
  418. - apiGroups:
  419. - ""
  420. resources:
  421. - endpoints
  422. verbs:
  423. - create
  424. - delete
  425. - get
  426. - list
  427. - update
  428. - apiGroups:
  429. - ""
  430. resources:
  431. - endpoints/restricted
  432. verbs:
  433. - create
  434. - apiGroups:
  435. - ""
  436. resources:
  437. - events
  438. verbs:
  439. - create
  440. - patch
  441. - update
  442. - apiVersion: rbac.authorization.k8s.io/v1
  443. kind: ClusterRole
  444. metadata:
  445. annotations:
  446. rbac.authorization.kubernetes.io/autoupdate: "true"
  447. creationTimestamp: null
  448. labels:
  449. kubernetes.io/bootstrapping: rbac-defaults
  450. name: system:controller:expand-controller
  451. rules:
  452. - apiGroups:
  453. - ""
  454. resources:
  455. - persistentvolumes
  456. verbs:
  457. - get
  458. - list
  459. - patch
  460. - update
  461. - watch
  462. - apiGroups:
  463. - ""
  464. resources:
  465. - persistentvolumeclaims/status
  466. verbs:
  467. - patch
  468. - update
  469. - apiGroups:
  470. - ""
  471. resources:
  472. - persistentvolumeclaims
  473. verbs:
  474. - get
  475. - list
  476. - watch
  477. - apiGroups:
  478. - storage.k8s.io
  479. resources:
  480. - storageclasses
  481. verbs:
  482. - get
  483. - list
  484. - watch
  485. - apiGroups:
  486. - ""
  487. resources:
  488. - endpoints
  489. - services
  490. verbs:
  491. - get
  492. - apiGroups:
  493. - ""
  494. resources:
  495. - secrets
  496. verbs:
  497. - get
  498. - apiGroups:
  499. - ""
  500. resources:
  501. - events
  502. verbs:
  503. - create
  504. - patch
  505. - update
  506. - apiVersion: rbac.authorization.k8s.io/v1
  507. kind: ClusterRole
  508. metadata:
  509. annotations:
  510. rbac.authorization.kubernetes.io/autoupdate: "true"
  511. creationTimestamp: null
  512. labels:
  513. kubernetes.io/bootstrapping: rbac-defaults
  514. name: system:controller:generic-garbage-collector
  515. rules:
  516. - apiGroups:
  517. - '*'
  518. resources:
  519. - '*'
  520. verbs:
  521. - delete
  522. - get
  523. - list
  524. - patch
  525. - update
  526. - watch
  527. - apiGroups:
  528. - ""
  529. resources:
  530. - events
  531. verbs:
  532. - create
  533. - patch
  534. - update
  535. - apiVersion: rbac.authorization.k8s.io/v1
  536. kind: ClusterRole
  537. metadata:
  538. annotations:
  539. rbac.authorization.kubernetes.io/autoupdate: "true"
  540. creationTimestamp: null
  541. labels:
  542. kubernetes.io/bootstrapping: rbac-defaults
  543. name: system:controller:horizontal-pod-autoscaler
  544. rules:
  545. - apiGroups:
  546. - autoscaling
  547. resources:
  548. - horizontalpodautoscalers
  549. verbs:
  550. - get
  551. - list
  552. - watch
  553. - apiGroups:
  554. - autoscaling
  555. resources:
  556. - horizontalpodautoscalers/status
  557. verbs:
  558. - update
  559. - apiGroups:
  560. - '*'
  561. resources:
  562. - '*/scale'
  563. verbs:
  564. - get
  565. - update
  566. - apiGroups:
  567. - ""
  568. resources:
  569. - pods
  570. verbs:
  571. - list
  572. - apiGroups:
  573. - ""
  574. resourceNames:
  575. - 'http:heapster:'
  576. - 'https:heapster:'
  577. resources:
  578. - services/proxy
  579. verbs:
  580. - get
  581. - apiGroups:
  582. - metrics.k8s.io
  583. resources:
  584. - pods
  585. verbs:
  586. - list
  587. - apiGroups:
  588. - custom.metrics.k8s.io
  589. resources:
  590. - '*'
  591. verbs:
  592. - get
  593. - list
  594. - apiGroups:
  595. - ""
  596. resources:
  597. - events
  598. verbs:
  599. - create
  600. - patch
  601. - update
  602. - apiVersion: rbac.authorization.k8s.io/v1
  603. kind: ClusterRole
  604. metadata:
  605. annotations:
  606. rbac.authorization.kubernetes.io/autoupdate: "true"
  607. creationTimestamp: null
  608. labels:
  609. kubernetes.io/bootstrapping: rbac-defaults
  610. name: system:controller:job-controller
  611. rules:
  612. - apiGroups:
  613. - batch
  614. resources:
  615. - jobs
  616. verbs:
  617. - get
  618. - list
  619. - update
  620. - watch
  621. - apiGroups:
  622. - batch
  623. resources:
  624. - jobs/status
  625. verbs:
  626. - update
  627. - apiGroups:
  628. - batch
  629. resources:
  630. - jobs/finalizers
  631. verbs:
  632. - update
  633. - apiGroups:
  634. - ""
  635. resources:
  636. - pods
  637. verbs:
  638. - create
  639. - delete
  640. - list
  641. - patch
  642. - watch
  643. - apiGroups:
  644. - ""
  645. resources:
  646. - events
  647. verbs:
  648. - create
  649. - patch
  650. - update
  651. - apiVersion: rbac.authorization.k8s.io/v1
  652. kind: ClusterRole
  653. metadata:
  654. annotations:
  655. rbac.authorization.kubernetes.io/autoupdate: "true"
  656. creationTimestamp: null
  657. labels:
  658. kubernetes.io/bootstrapping: rbac-defaults
  659. name: system:controller:namespace-controller
  660. rules:
  661. - apiGroups:
  662. - ""
  663. resources:
  664. - namespaces
  665. verbs:
  666. - delete
  667. - get
  668. - list
  669. - watch
  670. - apiGroups:
  671. - ""
  672. resources:
  673. - namespaces/finalize
  674. - namespaces/status
  675. verbs:
  676. - update
  677. - apiGroups:
  678. - '*'
  679. resources:
  680. - '*'
  681. verbs:
  682. - delete
  683. - deletecollection
  684. - get
  685. - list
  686. - apiVersion: rbac.authorization.k8s.io/v1
  687. kind: ClusterRole
  688. metadata:
  689. annotations:
  690. rbac.authorization.kubernetes.io/autoupdate: "true"
  691. creationTimestamp: null
  692. labels:
  693. kubernetes.io/bootstrapping: rbac-defaults
  694. name: system:controller:node-controller
  695. rules:
  696. - apiGroups:
  697. - ""
  698. resources:
  699. - nodes
  700. verbs:
  701. - delete
  702. - get
  703. - list
  704. - patch
  705. - update
  706. - apiGroups:
  707. - ""
  708. resources:
  709. - nodes/status
  710. verbs:
  711. - patch
  712. - update
  713. - apiGroups:
  714. - ""
  715. resources:
  716. - pods/status
  717. verbs:
  718. - update
  719. - apiGroups:
  720. - ""
  721. resources:
  722. - pods
  723. verbs:
  724. - delete
  725. - list
  726. - apiGroups:
  727. - ""
  728. resources:
  729. - events
  730. verbs:
  731. - create
  732. - patch
  733. - update
  734. - apiVersion: rbac.authorization.k8s.io/v1
  735. kind: ClusterRole
  736. metadata:
  737. annotations:
  738. rbac.authorization.kubernetes.io/autoupdate: "true"
  739. creationTimestamp: null
  740. labels:
  741. kubernetes.io/bootstrapping: rbac-defaults
  742. name: system:controller:persistent-volume-binder
  743. rules:
  744. - apiGroups:
  745. - ""
  746. resources:
  747. - persistentvolumes
  748. verbs:
  749. - create
  750. - delete
  751. - get
  752. - list
  753. - update
  754. - watch
  755. - apiGroups:
  756. - ""
  757. resources:
  758. - persistentvolumes/status
  759. verbs:
  760. - update
  761. - apiGroups:
  762. - ""
  763. resources:
  764. - persistentvolumeclaims
  765. verbs:
  766. - get
  767. - list
  768. - update
  769. - watch
  770. - apiGroups:
  771. - ""
  772. resources:
  773. - persistentvolumeclaims/status
  774. verbs:
  775. - update
  776. - apiGroups:
  777. - ""
  778. resources:
  779. - pods
  780. verbs:
  781. - create
  782. - delete
  783. - get
  784. - list
  785. - watch
  786. - apiGroups:
  787. - storage.k8s.io
  788. resources:
  789. - storageclasses
  790. verbs:
  791. - get
  792. - list
  793. - watch
  794. - apiGroups:
  795. - ""
  796. resources:
  797. - endpoints
  798. verbs:
  799. - create
  800. - delete
  801. - get
  802. - update
  803. - apiGroups:
  804. - ""
  805. resources:
  806. - services
  807. verbs:
  808. - create
  809. - delete
  810. - get
  811. - apiGroups:
  812. - ""
  813. resources:
  814. - secrets
  815. verbs:
  816. - get
  817. - apiGroups:
  818. - ""
  819. resources:
  820. - nodes
  821. verbs:
  822. - get
  823. - list
  824. - apiGroups:
  825. - ""
  826. resources:
  827. - events
  828. verbs:
  829. - watch
  830. - apiGroups:
  831. - ""
  832. resources:
  833. - events
  834. verbs:
  835. - create
  836. - patch
  837. - update
  838. - apiVersion: rbac.authorization.k8s.io/v1
  839. kind: ClusterRole
  840. metadata:
  841. annotations:
  842. rbac.authorization.kubernetes.io/autoupdate: "true"
  843. creationTimestamp: null
  844. labels:
  845. kubernetes.io/bootstrapping: rbac-defaults
  846. name: system:controller:pod-garbage-collector
  847. rules:
  848. - apiGroups:
  849. - ""
  850. resources:
  851. - pods
  852. verbs:
  853. - delete
  854. - list
  855. - watch
  856. - apiGroups:
  857. - ""
  858. resources:
  859. - nodes
  860. verbs:
  861. - list
  862. - apiVersion: rbac.authorization.k8s.io/v1
  863. kind: ClusterRole
  864. metadata:
  865. annotations:
  866. rbac.authorization.kubernetes.io/autoupdate: "true"
  867. creationTimestamp: null
  868. labels:
  869. kubernetes.io/bootstrapping: rbac-defaults
  870. name: system:controller:pv-protection-controller
  871. rules:
  872. - apiGroups:
  873. - ""
  874. resources:
  875. - persistentvolumes
  876. verbs:
  877. - get
  878. - list
  879. - update
  880. - watch
  881. - apiGroups:
  882. - ""
  883. resources:
  884. - events
  885. verbs:
  886. - create
  887. - patch
  888. - update
  889. - apiVersion: rbac.authorization.k8s.io/v1
  890. kind: ClusterRole
  891. metadata:
  892. annotations:
  893. rbac.authorization.kubernetes.io/autoupdate: "true"
  894. creationTimestamp: null
  895. labels:
  896. kubernetes.io/bootstrapping: rbac-defaults
  897. name: system:controller:pvc-protection-controller
  898. rules:
  899. - apiGroups:
  900. - ""
  901. resources:
  902. - persistentvolumeclaims
  903. verbs:
  904. - get
  905. - list
  906. - update
  907. - watch
  908. - apiGroups:
  909. - ""
  910. resources:
  911. - pods
  912. verbs:
  913. - get
  914. - list
  915. - watch
  916. - apiGroups:
  917. - ""
  918. resources:
  919. - events
  920. verbs:
  921. - create
  922. - patch
  923. - update
  924. - apiVersion: rbac.authorization.k8s.io/v1
  925. kind: ClusterRole
  926. metadata:
  927. annotations:
  928. rbac.authorization.kubernetes.io/autoupdate: "true"
  929. creationTimestamp: null
  930. labels:
  931. kubernetes.io/bootstrapping: rbac-defaults
  932. name: system:controller:replicaset-controller
  933. rules:
  934. - apiGroups:
  935. - apps
  936. - extensions
  937. resources:
  938. - replicasets
  939. verbs:
  940. - get
  941. - list
  942. - update
  943. - watch
  944. - apiGroups:
  945. - apps
  946. - extensions
  947. resources:
  948. - replicasets/status
  949. verbs:
  950. - update
  951. - apiGroups:
  952. - apps
  953. - extensions
  954. resources:
  955. - replicasets/finalizers
  956. verbs:
  957. - update
  958. - apiGroups:
  959. - ""
  960. resources:
  961. - pods
  962. verbs:
  963. - create
  964. - delete
  965. - list
  966. - patch
  967. - watch
  968. - apiGroups:
  969. - ""
  970. resources:
  971. - events
  972. verbs:
  973. - create
  974. - patch
  975. - update
  976. - apiVersion: rbac.authorization.k8s.io/v1
  977. kind: ClusterRole
  978. metadata:
  979. annotations:
  980. rbac.authorization.kubernetes.io/autoupdate: "true"
  981. creationTimestamp: null
  982. labels:
  983. kubernetes.io/bootstrapping: rbac-defaults
  984. name: system:controller:replication-controller
  985. rules:
  986. - apiGroups:
  987. - ""
  988. resources:
  989. - replicationcontrollers
  990. verbs:
  991. - get
  992. - list
  993. - update
  994. - watch
  995. - apiGroups:
  996. - ""
  997. resources:
  998. - replicationcontrollers/status
  999. verbs:
  1000. - update
  1001. - apiGroups:
  1002. - ""
  1003. resources:
  1004. - replicationcontrollers/finalizers
  1005. verbs:
  1006. - update
  1007. - apiGroups:
  1008. - ""
  1009. resources:
  1010. - pods
  1011. verbs:
  1012. - create
  1013. - delete
  1014. - list
  1015. - patch
  1016. - watch
  1017. - apiGroups:
  1018. - ""
  1019. resources:
  1020. - events
  1021. verbs:
  1022. - create
  1023. - patch
  1024. - update
  1025. - apiVersion: rbac.authorization.k8s.io/v1
  1026. kind: ClusterRole
  1027. metadata:
  1028. annotations:
  1029. rbac.authorization.kubernetes.io/autoupdate: "true"
  1030. creationTimestamp: null
  1031. labels:
  1032. kubernetes.io/bootstrapping: rbac-defaults
  1033. name: system:controller:resourcequota-controller
  1034. rules:
  1035. - apiGroups:
  1036. - '*'
  1037. resources:
  1038. - '*'
  1039. verbs:
  1040. - list
  1041. - watch
  1042. - apiGroups:
  1043. - ""
  1044. resources:
  1045. - resourcequotas/status
  1046. verbs:
  1047. - update
  1048. - apiGroups:
  1049. - ""
  1050. resources:
  1051. - events
  1052. verbs:
  1053. - create
  1054. - patch
  1055. - update
  1056. - apiVersion: rbac.authorization.k8s.io/v1
  1057. kind: ClusterRole
  1058. metadata:
  1059. annotations:
  1060. rbac.authorization.kubernetes.io/autoupdate: "true"
  1061. creationTimestamp: null
  1062. labels:
  1063. kubernetes.io/bootstrapping: rbac-defaults
  1064. name: system:controller:route-controller
  1065. rules:
  1066. - apiGroups:
  1067. - ""
  1068. resources:
  1069. - nodes
  1070. verbs:
  1071. - list
  1072. - watch
  1073. - apiGroups:
  1074. - ""
  1075. resources:
  1076. - nodes/status
  1077. verbs:
  1078. - patch
  1079. - apiGroups:
  1080. - ""
  1081. resources:
  1082. - events
  1083. verbs:
  1084. - create
  1085. - patch
  1086. - update
  1087. - apiVersion: rbac.authorization.k8s.io/v1
  1088. kind: ClusterRole
  1089. metadata:
  1090. annotations:
  1091. rbac.authorization.kubernetes.io/autoupdate: "true"
  1092. creationTimestamp: null
  1093. labels:
  1094. kubernetes.io/bootstrapping: rbac-defaults
  1095. name: system:controller:service-account-controller
  1096. rules:
  1097. - apiGroups:
  1098. - ""
  1099. resources:
  1100. - serviceaccounts
  1101. verbs:
  1102. - create
  1103. - apiGroups:
  1104. - ""
  1105. resources:
  1106. - events
  1107. verbs:
  1108. - create
  1109. - patch
  1110. - update
  1111. - apiVersion: rbac.authorization.k8s.io/v1
  1112. kind: ClusterRole
  1113. metadata:
  1114. annotations:
  1115. rbac.authorization.kubernetes.io/autoupdate: "true"
  1116. creationTimestamp: null
  1117. labels:
  1118. kubernetes.io/bootstrapping: rbac-defaults
  1119. name: system:controller:service-controller
  1120. rules:
  1121. - apiGroups:
  1122. - ""
  1123. resources:
  1124. - services
  1125. verbs:
  1126. - get
  1127. - list
  1128. - watch
  1129. - apiGroups:
  1130. - ""
  1131. resources:
  1132. - services/status
  1133. verbs:
  1134. - patch
  1135. - update
  1136. - apiGroups:
  1137. - ""
  1138. resources:
  1139. - nodes
  1140. verbs:
  1141. - list
  1142. - watch
  1143. - apiGroups:
  1144. - ""
  1145. resources:
  1146. - events
  1147. verbs:
  1148. - create
  1149. - patch
  1150. - update
  1151. - apiVersion: rbac.authorization.k8s.io/v1
  1152. kind: ClusterRole
  1153. metadata:
  1154. annotations:
  1155. rbac.authorization.kubernetes.io/autoupdate: "true"
  1156. creationTimestamp: null
  1157. labels:
  1158. kubernetes.io/bootstrapping: rbac-defaults
  1159. name: system:controller:statefulset-controller
  1160. rules:
  1161. - apiGroups:
  1162. - ""
  1163. resources:
  1164. - pods
  1165. verbs:
  1166. - list
  1167. - watch
  1168. - apiGroups:
  1169. - apps
  1170. resources:
  1171. - statefulsets
  1172. verbs:
  1173. - get
  1174. - list
  1175. - watch
  1176. - apiGroups:
  1177. - apps
  1178. resources:
  1179. - statefulsets/status
  1180. verbs:
  1181. - update
  1182. - apiGroups:
  1183. - apps
  1184. resources:
  1185. - statefulsets/finalizers
  1186. verbs:
  1187. - update
  1188. - apiGroups:
  1189. - ""
  1190. resources:
  1191. - pods
  1192. verbs:
  1193. - create
  1194. - delete
  1195. - get
  1196. - patch
  1197. - update
  1198. - apiGroups:
  1199. - apps
  1200. resources:
  1201. - controllerrevisions
  1202. verbs:
  1203. - create
  1204. - delete
  1205. - get
  1206. - list
  1207. - patch
  1208. - update
  1209. - watch
  1210. - apiGroups:
  1211. - ""
  1212. resources:
  1213. - persistentvolumeclaims
  1214. verbs:
  1215. - create
  1216. - get
  1217. - apiGroups:
  1218. - ""
  1219. resources:
  1220. - events
  1221. verbs:
  1222. - create
  1223. - patch
  1224. - update
  1225. - apiVersion: rbac.authorization.k8s.io/v1
  1226. kind: ClusterRole
  1227. metadata:
  1228. annotations:
  1229. rbac.authorization.kubernetes.io/autoupdate: "true"
  1230. creationTimestamp: null
  1231. labels:
  1232. kubernetes.io/bootstrapping: rbac-defaults
  1233. name: system:controller:ttl-controller
  1234. rules:
  1235. - apiGroups:
  1236. - ""
  1237. resources:
  1238. - nodes
  1239. verbs:
  1240. - list
  1241. - patch
  1242. - update
  1243. - watch
  1244. - apiGroups:
  1245. - ""
  1246. resources:
  1247. - events
  1248. verbs:
  1249. - create
  1250. - patch
  1251. - update
  1252. kind: List
  1253. metadata: {}