controller-roles.yaml 22 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326
  1. apiVersion: v1
  2. items:
  3. - apiVersion: rbac.authorization.k8s.io/v1
  4. kind: ClusterRole
  5. metadata:
  6. annotations:
  7. rbac.authorization.kubernetes.io/autoupdate: "true"
  8. creationTimestamp: null
  9. labels:
  10. kubernetes.io/bootstrapping: rbac-defaults
  11. name: system:controller:attachdetach-controller
  12. rules:
  13. - apiGroups:
  14. - ""
  15. resources:
  16. - persistentvolumeclaims
  17. - persistentvolumes
  18. verbs:
  19. - list
  20. - watch
  21. - apiGroups:
  22. - ""
  23. resources:
  24. - nodes
  25. verbs:
  26. - get
  27. - list
  28. - watch
  29. - apiGroups:
  30. - ""
  31. resources:
  32. - nodes/status
  33. verbs:
  34. - patch
  35. - update
  36. - apiGroups:
  37. - ""
  38. resources:
  39. - pods
  40. verbs:
  41. - list
  42. - watch
  43. - apiGroups:
  44. - ""
  45. - events.k8s.io
  46. resources:
  47. - events
  48. verbs:
  49. - create
  50. - patch
  51. - update
  52. - apiGroups:
  53. - storage.k8s.io
  54. resources:
  55. - volumeattachments
  56. verbs:
  57. - create
  58. - delete
  59. - get
  60. - list
  61. - watch
  62. - apiGroups:
  63. - storage.k8s.io
  64. resources:
  65. - csidrivers
  66. verbs:
  67. - get
  68. - list
  69. - watch
  70. - apiGroups:
  71. - storage.k8s.io
  72. resources:
  73. - csinodes
  74. verbs:
  75. - get
  76. - list
  77. - watch
  78. - apiVersion: rbac.authorization.k8s.io/v1
  79. kind: ClusterRole
  80. metadata:
  81. annotations:
  82. rbac.authorization.kubernetes.io/autoupdate: "true"
  83. creationTimestamp: null
  84. labels:
  85. kubernetes.io/bootstrapping: rbac-defaults
  86. name: system:controller:certificate-controller
  87. rules:
  88. - apiGroups:
  89. - certificates.k8s.io
  90. resources:
  91. - certificatesigningrequests
  92. verbs:
  93. - delete
  94. - get
  95. - list
  96. - watch
  97. - apiGroups:
  98. - certificates.k8s.io
  99. resources:
  100. - certificatesigningrequests/approval
  101. - certificatesigningrequests/status
  102. verbs:
  103. - update
  104. - apiGroups:
  105. - authorization.k8s.io
  106. resources:
  107. - subjectaccessreviews
  108. verbs:
  109. - create
  110. - apiGroups:
  111. - ""
  112. - events.k8s.io
  113. resources:
  114. - events
  115. verbs:
  116. - create
  117. - patch
  118. - update
  119. - apiVersion: rbac.authorization.k8s.io/v1
  120. kind: ClusterRole
  121. metadata:
  122. annotations:
  123. rbac.authorization.kubernetes.io/autoupdate: "true"
  124. creationTimestamp: null
  125. labels:
  126. kubernetes.io/bootstrapping: rbac-defaults
  127. name: system:controller:clusterrole-aggregation-controller
  128. rules:
  129. - apiGroups:
  130. - rbac.authorization.k8s.io
  131. resources:
  132. - clusterroles
  133. verbs:
  134. - escalate
  135. - get
  136. - list
  137. - patch
  138. - update
  139. - watch
  140. - apiVersion: rbac.authorization.k8s.io/v1
  141. kind: ClusterRole
  142. metadata:
  143. annotations:
  144. rbac.authorization.kubernetes.io/autoupdate: "true"
  145. creationTimestamp: null
  146. labels:
  147. kubernetes.io/bootstrapping: rbac-defaults
  148. name: system:controller:cronjob-controller
  149. rules:
  150. - apiGroups:
  151. - batch
  152. resources:
  153. - cronjobs
  154. verbs:
  155. - get
  156. - list
  157. - update
  158. - watch
  159. - apiGroups:
  160. - batch
  161. resources:
  162. - jobs
  163. verbs:
  164. - create
  165. - delete
  166. - get
  167. - list
  168. - patch
  169. - update
  170. - watch
  171. - apiGroups:
  172. - batch
  173. resources:
  174. - cronjobs/status
  175. verbs:
  176. - update
  177. - apiGroups:
  178. - batch
  179. resources:
  180. - cronjobs/finalizers
  181. verbs:
  182. - update
  183. - apiGroups:
  184. - ""
  185. resources:
  186. - pods
  187. verbs:
  188. - delete
  189. - list
  190. - apiGroups:
  191. - ""
  192. - events.k8s.io
  193. resources:
  194. - events
  195. verbs:
  196. - create
  197. - patch
  198. - update
  199. - apiVersion: rbac.authorization.k8s.io/v1
  200. kind: ClusterRole
  201. metadata:
  202. annotations:
  203. rbac.authorization.kubernetes.io/autoupdate: "true"
  204. creationTimestamp: null
  205. labels:
  206. kubernetes.io/bootstrapping: rbac-defaults
  207. name: system:controller:daemon-set-controller
  208. rules:
  209. - apiGroups:
  210. - apps
  211. - extensions
  212. resources:
  213. - daemonsets
  214. verbs:
  215. - get
  216. - list
  217. - watch
  218. - apiGroups:
  219. - apps
  220. - extensions
  221. resources:
  222. - daemonsets/status
  223. verbs:
  224. - update
  225. - apiGroups:
  226. - apps
  227. - extensions
  228. resources:
  229. - daemonsets/finalizers
  230. verbs:
  231. - update
  232. - apiGroups:
  233. - ""
  234. resources:
  235. - nodes
  236. verbs:
  237. - list
  238. - watch
  239. - apiGroups:
  240. - ""
  241. resources:
  242. - pods
  243. verbs:
  244. - create
  245. - delete
  246. - list
  247. - patch
  248. - watch
  249. - apiGroups:
  250. - ""
  251. resources:
  252. - pods/binding
  253. verbs:
  254. - create
  255. - apiGroups:
  256. - apps
  257. resources:
  258. - controllerrevisions
  259. verbs:
  260. - create
  261. - delete
  262. - get
  263. - list
  264. - patch
  265. - update
  266. - watch
  267. - apiGroups:
  268. - ""
  269. - events.k8s.io
  270. resources:
  271. - events
  272. verbs:
  273. - create
  274. - patch
  275. - update
  276. - apiVersion: rbac.authorization.k8s.io/v1
  277. kind: ClusterRole
  278. metadata:
  279. annotations:
  280. rbac.authorization.kubernetes.io/autoupdate: "true"
  281. creationTimestamp: null
  282. labels:
  283. kubernetes.io/bootstrapping: rbac-defaults
  284. name: system:controller:deployment-controller
  285. rules:
  286. - apiGroups:
  287. - apps
  288. - extensions
  289. resources:
  290. - deployments
  291. verbs:
  292. - get
  293. - list
  294. - update
  295. - watch
  296. - apiGroups:
  297. - apps
  298. - extensions
  299. resources:
  300. - deployments/status
  301. verbs:
  302. - update
  303. - apiGroups:
  304. - apps
  305. - extensions
  306. resources:
  307. - deployments/finalizers
  308. verbs:
  309. - update
  310. - apiGroups:
  311. - apps
  312. - extensions
  313. resources:
  314. - replicasets
  315. verbs:
  316. - create
  317. - delete
  318. - get
  319. - list
  320. - patch
  321. - update
  322. - watch
  323. - apiGroups:
  324. - ""
  325. resources:
  326. - pods
  327. verbs:
  328. - get
  329. - list
  330. - update
  331. - watch
  332. - apiGroups:
  333. - ""
  334. - events.k8s.io
  335. resources:
  336. - events
  337. verbs:
  338. - create
  339. - patch
  340. - update
  341. - apiVersion: rbac.authorization.k8s.io/v1
  342. kind: ClusterRole
  343. metadata:
  344. annotations:
  345. rbac.authorization.kubernetes.io/autoupdate: "true"
  346. creationTimestamp: null
  347. labels:
  348. kubernetes.io/bootstrapping: rbac-defaults
  349. name: system:controller:disruption-controller
  350. rules:
  351. - apiGroups:
  352. - apps
  353. - extensions
  354. resources:
  355. - deployments
  356. verbs:
  357. - get
  358. - list
  359. - watch
  360. - apiGroups:
  361. - apps
  362. - extensions
  363. resources:
  364. - replicasets
  365. verbs:
  366. - get
  367. - list
  368. - watch
  369. - apiGroups:
  370. - ""
  371. resources:
  372. - replicationcontrollers
  373. verbs:
  374. - get
  375. - list
  376. - watch
  377. - apiGroups:
  378. - policy
  379. resources:
  380. - poddisruptionbudgets
  381. verbs:
  382. - get
  383. - list
  384. - watch
  385. - apiGroups:
  386. - apps
  387. resources:
  388. - statefulsets
  389. verbs:
  390. - get
  391. - list
  392. - watch
  393. - apiGroups:
  394. - policy
  395. resources:
  396. - poddisruptionbudgets/status
  397. verbs:
  398. - update
  399. - apiGroups:
  400. - '*'
  401. resources:
  402. - '*/scale'
  403. verbs:
  404. - get
  405. - apiGroups:
  406. - ""
  407. - events.k8s.io
  408. resources:
  409. - events
  410. verbs:
  411. - create
  412. - patch
  413. - update
  414. - apiVersion: rbac.authorization.k8s.io/v1
  415. kind: ClusterRole
  416. metadata:
  417. annotations:
  418. rbac.authorization.kubernetes.io/autoupdate: "true"
  419. creationTimestamp: null
  420. labels:
  421. kubernetes.io/bootstrapping: rbac-defaults
  422. name: system:controller:endpoint-controller
  423. rules:
  424. - apiGroups:
  425. - ""
  426. resources:
  427. - pods
  428. - services
  429. verbs:
  430. - get
  431. - list
  432. - watch
  433. - apiGroups:
  434. - ""
  435. resources:
  436. - endpoints
  437. verbs:
  438. - create
  439. - delete
  440. - get
  441. - list
  442. - update
  443. - apiGroups:
  444. - ""
  445. resources:
  446. - endpoints/restricted
  447. verbs:
  448. - create
  449. - apiGroups:
  450. - ""
  451. - events.k8s.io
  452. resources:
  453. - events
  454. verbs:
  455. - create
  456. - patch
  457. - update
  458. - apiVersion: rbac.authorization.k8s.io/v1
  459. kind: ClusterRole
  460. metadata:
  461. annotations:
  462. rbac.authorization.kubernetes.io/autoupdate: "true"
  463. creationTimestamp: null
  464. labels:
  465. kubernetes.io/bootstrapping: rbac-defaults
  466. name: system:controller:endpointslice-controller
  467. rules:
  468. - apiGroups:
  469. - ""
  470. resources:
  471. - nodes
  472. - pods
  473. - services
  474. verbs:
  475. - get
  476. - list
  477. - watch
  478. - apiGroups:
  479. - discovery.k8s.io
  480. resources:
  481. - endpointslices
  482. verbs:
  483. - create
  484. - delete
  485. - get
  486. - list
  487. - update
  488. - apiGroups:
  489. - ""
  490. - events.k8s.io
  491. resources:
  492. - events
  493. verbs:
  494. - create
  495. - patch
  496. - update
  497. - apiVersion: rbac.authorization.k8s.io/v1
  498. kind: ClusterRole
  499. metadata:
  500. annotations:
  501. rbac.authorization.kubernetes.io/autoupdate: "true"
  502. creationTimestamp: null
  503. labels:
  504. kubernetes.io/bootstrapping: rbac-defaults
  505. name: system:controller:expand-controller
  506. rules:
  507. - apiGroups:
  508. - ""
  509. resources:
  510. - persistentvolumes
  511. verbs:
  512. - get
  513. - list
  514. - patch
  515. - update
  516. - watch
  517. - apiGroups:
  518. - ""
  519. resources:
  520. - persistentvolumeclaims/status
  521. verbs:
  522. - patch
  523. - update
  524. - apiGroups:
  525. - ""
  526. resources:
  527. - persistentvolumeclaims
  528. verbs:
  529. - get
  530. - list
  531. - watch
  532. - apiGroups:
  533. - storage.k8s.io
  534. resources:
  535. - storageclasses
  536. verbs:
  537. - get
  538. - list
  539. - watch
  540. - apiGroups:
  541. - ""
  542. resources:
  543. - endpoints
  544. - services
  545. verbs:
  546. - get
  547. - apiGroups:
  548. - ""
  549. resources:
  550. - secrets
  551. verbs:
  552. - get
  553. - apiGroups:
  554. - ""
  555. - events.k8s.io
  556. resources:
  557. - events
  558. verbs:
  559. - create
  560. - patch
  561. - update
  562. - apiVersion: rbac.authorization.k8s.io/v1
  563. kind: ClusterRole
  564. metadata:
  565. annotations:
  566. rbac.authorization.kubernetes.io/autoupdate: "true"
  567. creationTimestamp: null
  568. labels:
  569. kubernetes.io/bootstrapping: rbac-defaults
  570. name: system:controller:generic-garbage-collector
  571. rules:
  572. - apiGroups:
  573. - '*'
  574. resources:
  575. - '*'
  576. verbs:
  577. - delete
  578. - get
  579. - list
  580. - patch
  581. - update
  582. - watch
  583. - apiGroups:
  584. - ""
  585. - events.k8s.io
  586. resources:
  587. - events
  588. verbs:
  589. - create
  590. - patch
  591. - update
  592. - apiVersion: rbac.authorization.k8s.io/v1
  593. kind: ClusterRole
  594. metadata:
  595. annotations:
  596. rbac.authorization.kubernetes.io/autoupdate: "true"
  597. creationTimestamp: null
  598. labels:
  599. kubernetes.io/bootstrapping: rbac-defaults
  600. name: system:controller:horizontal-pod-autoscaler
  601. rules:
  602. - apiGroups:
  603. - autoscaling
  604. resources:
  605. - horizontalpodautoscalers
  606. verbs:
  607. - get
  608. - list
  609. - watch
  610. - apiGroups:
  611. - autoscaling
  612. resources:
  613. - horizontalpodautoscalers/status
  614. verbs:
  615. - update
  616. - apiGroups:
  617. - '*'
  618. resources:
  619. - '*/scale'
  620. verbs:
  621. - get
  622. - update
  623. - apiGroups:
  624. - ""
  625. resources:
  626. - pods
  627. verbs:
  628. - list
  629. - apiGroups:
  630. - ""
  631. resourceNames:
  632. - 'http:heapster:'
  633. - 'https:heapster:'
  634. resources:
  635. - services/proxy
  636. verbs:
  637. - get
  638. - apiGroups:
  639. - metrics.k8s.io
  640. resources:
  641. - pods
  642. verbs:
  643. - list
  644. - apiGroups:
  645. - custom.metrics.k8s.io
  646. resources:
  647. - '*'
  648. verbs:
  649. - get
  650. - list
  651. - apiGroups:
  652. - ""
  653. - events.k8s.io
  654. resources:
  655. - events
  656. verbs:
  657. - create
  658. - patch
  659. - update
  660. - apiVersion: rbac.authorization.k8s.io/v1
  661. kind: ClusterRole
  662. metadata:
  663. annotations:
  664. rbac.authorization.kubernetes.io/autoupdate: "true"
  665. creationTimestamp: null
  666. labels:
  667. kubernetes.io/bootstrapping: rbac-defaults
  668. name: system:controller:job-controller
  669. rules:
  670. - apiGroups:
  671. - batch
  672. resources:
  673. - jobs
  674. verbs:
  675. - get
  676. - list
  677. - update
  678. - watch
  679. - apiGroups:
  680. - batch
  681. resources:
  682. - jobs/status
  683. verbs:
  684. - update
  685. - apiGroups:
  686. - batch
  687. resources:
  688. - jobs/finalizers
  689. verbs:
  690. - update
  691. - apiGroups:
  692. - ""
  693. resources:
  694. - pods
  695. verbs:
  696. - create
  697. - delete
  698. - list
  699. - patch
  700. - watch
  701. - apiGroups:
  702. - ""
  703. - events.k8s.io
  704. resources:
  705. - events
  706. verbs:
  707. - create
  708. - patch
  709. - update
  710. - apiVersion: rbac.authorization.k8s.io/v1
  711. kind: ClusterRole
  712. metadata:
  713. annotations:
  714. rbac.authorization.kubernetes.io/autoupdate: "true"
  715. creationTimestamp: null
  716. labels:
  717. kubernetes.io/bootstrapping: rbac-defaults
  718. name: system:controller:namespace-controller
  719. rules:
  720. - apiGroups:
  721. - ""
  722. resources:
  723. - namespaces
  724. verbs:
  725. - delete
  726. - get
  727. - list
  728. - watch
  729. - apiGroups:
  730. - ""
  731. resources:
  732. - namespaces/finalize
  733. - namespaces/status
  734. verbs:
  735. - update
  736. - apiGroups:
  737. - '*'
  738. resources:
  739. - '*'
  740. verbs:
  741. - delete
  742. - deletecollection
  743. - get
  744. - list
  745. - apiVersion: rbac.authorization.k8s.io/v1
  746. kind: ClusterRole
  747. metadata:
  748. annotations:
  749. rbac.authorization.kubernetes.io/autoupdate: "true"
  750. creationTimestamp: null
  751. labels:
  752. kubernetes.io/bootstrapping: rbac-defaults
  753. name: system:controller:node-controller
  754. rules:
  755. - apiGroups:
  756. - ""
  757. resources:
  758. - nodes
  759. verbs:
  760. - delete
  761. - get
  762. - list
  763. - patch
  764. - update
  765. - apiGroups:
  766. - ""
  767. resources:
  768. - nodes/status
  769. verbs:
  770. - patch
  771. - update
  772. - apiGroups:
  773. - ""
  774. resources:
  775. - pods/status
  776. verbs:
  777. - update
  778. - apiGroups:
  779. - ""
  780. resources:
  781. - pods
  782. verbs:
  783. - delete
  784. - list
  785. - apiGroups:
  786. - ""
  787. - events.k8s.io
  788. resources:
  789. - events
  790. verbs:
  791. - create
  792. - patch
  793. - update
  794. - apiVersion: rbac.authorization.k8s.io/v1
  795. kind: ClusterRole
  796. metadata:
  797. annotations:
  798. rbac.authorization.kubernetes.io/autoupdate: "true"
  799. creationTimestamp: null
  800. labels:
  801. kubernetes.io/bootstrapping: rbac-defaults
  802. name: system:controller:persistent-volume-binder
  803. rules:
  804. - apiGroups:
  805. - ""
  806. resources:
  807. - persistentvolumes
  808. verbs:
  809. - create
  810. - delete
  811. - get
  812. - list
  813. - update
  814. - watch
  815. - apiGroups:
  816. - ""
  817. resources:
  818. - persistentvolumes/status
  819. verbs:
  820. - update
  821. - apiGroups:
  822. - ""
  823. resources:
  824. - persistentvolumeclaims
  825. verbs:
  826. - get
  827. - list
  828. - update
  829. - watch
  830. - apiGroups:
  831. - ""
  832. resources:
  833. - persistentvolumeclaims/status
  834. verbs:
  835. - update
  836. - apiGroups:
  837. - ""
  838. resources:
  839. - pods
  840. verbs:
  841. - create
  842. - delete
  843. - get
  844. - list
  845. - watch
  846. - apiGroups:
  847. - storage.k8s.io
  848. resources:
  849. - storageclasses
  850. verbs:
  851. - get
  852. - list
  853. - watch
  854. - apiGroups:
  855. - ""
  856. resources:
  857. - endpoints
  858. verbs:
  859. - create
  860. - delete
  861. - get
  862. - update
  863. - apiGroups:
  864. - ""
  865. resources:
  866. - services
  867. verbs:
  868. - create
  869. - delete
  870. - get
  871. - apiGroups:
  872. - ""
  873. resources:
  874. - secrets
  875. verbs:
  876. - get
  877. - apiGroups:
  878. - ""
  879. resources:
  880. - nodes
  881. verbs:
  882. - get
  883. - list
  884. - apiGroups:
  885. - ""
  886. resources:
  887. - events
  888. verbs:
  889. - watch
  890. - apiGroups:
  891. - ""
  892. - events.k8s.io
  893. resources:
  894. - events
  895. verbs:
  896. - create
  897. - patch
  898. - update
  899. - apiVersion: rbac.authorization.k8s.io/v1
  900. kind: ClusterRole
  901. metadata:
  902. annotations:
  903. rbac.authorization.kubernetes.io/autoupdate: "true"
  904. creationTimestamp: null
  905. labels:
  906. kubernetes.io/bootstrapping: rbac-defaults
  907. name: system:controller:pod-garbage-collector
  908. rules:
  909. - apiGroups:
  910. - ""
  911. resources:
  912. - pods
  913. verbs:
  914. - delete
  915. - list
  916. - watch
  917. - apiGroups:
  918. - ""
  919. resources:
  920. - nodes
  921. verbs:
  922. - get
  923. - list
  924. - apiVersion: rbac.authorization.k8s.io/v1
  925. kind: ClusterRole
  926. metadata:
  927. annotations:
  928. rbac.authorization.kubernetes.io/autoupdate: "true"
  929. creationTimestamp: null
  930. labels:
  931. kubernetes.io/bootstrapping: rbac-defaults
  932. name: system:controller:pv-protection-controller
  933. rules:
  934. - apiGroups:
  935. - ""
  936. resources:
  937. - persistentvolumes
  938. verbs:
  939. - get
  940. - list
  941. - update
  942. - watch
  943. - apiGroups:
  944. - ""
  945. - events.k8s.io
  946. resources:
  947. - events
  948. verbs:
  949. - create
  950. - patch
  951. - update
  952. - apiVersion: rbac.authorization.k8s.io/v1
  953. kind: ClusterRole
  954. metadata:
  955. annotations:
  956. rbac.authorization.kubernetes.io/autoupdate: "true"
  957. creationTimestamp: null
  958. labels:
  959. kubernetes.io/bootstrapping: rbac-defaults
  960. name: system:controller:pvc-protection-controller
  961. rules:
  962. - apiGroups:
  963. - ""
  964. resources:
  965. - persistentvolumeclaims
  966. verbs:
  967. - get
  968. - list
  969. - update
  970. - watch
  971. - apiGroups:
  972. - ""
  973. resources:
  974. - pods
  975. verbs:
  976. - get
  977. - list
  978. - watch
  979. - apiGroups:
  980. - ""
  981. - events.k8s.io
  982. resources:
  983. - events
  984. verbs:
  985. - create
  986. - patch
  987. - update
  988. - apiVersion: rbac.authorization.k8s.io/v1
  989. kind: ClusterRole
  990. metadata:
  991. annotations:
  992. rbac.authorization.kubernetes.io/autoupdate: "true"
  993. creationTimestamp: null
  994. labels:
  995. kubernetes.io/bootstrapping: rbac-defaults
  996. name: system:controller:replicaset-controller
  997. rules:
  998. - apiGroups:
  999. - apps
  1000. - extensions
  1001. resources:
  1002. - replicasets
  1003. verbs:
  1004. - get
  1005. - list
  1006. - update
  1007. - watch
  1008. - apiGroups:
  1009. - apps
  1010. - extensions
  1011. resources:
  1012. - replicasets/status
  1013. verbs:
  1014. - update
  1015. - apiGroups:
  1016. - apps
  1017. - extensions
  1018. resources:
  1019. - replicasets/finalizers
  1020. verbs:
  1021. - update
  1022. - apiGroups:
  1023. - ""
  1024. resources:
  1025. - pods
  1026. verbs:
  1027. - create
  1028. - delete
  1029. - list
  1030. - patch
  1031. - watch
  1032. - apiGroups:
  1033. - ""
  1034. - events.k8s.io
  1035. resources:
  1036. - events
  1037. verbs:
  1038. - create
  1039. - patch
  1040. - update
  1041. - apiVersion: rbac.authorization.k8s.io/v1
  1042. kind: ClusterRole
  1043. metadata:
  1044. annotations:
  1045. rbac.authorization.kubernetes.io/autoupdate: "true"
  1046. creationTimestamp: null
  1047. labels:
  1048. kubernetes.io/bootstrapping: rbac-defaults
  1049. name: system:controller:replication-controller
  1050. rules:
  1051. - apiGroups:
  1052. - ""
  1053. resources:
  1054. - replicationcontrollers
  1055. verbs:
  1056. - get
  1057. - list
  1058. - update
  1059. - watch
  1060. - apiGroups:
  1061. - ""
  1062. resources:
  1063. - replicationcontrollers/status
  1064. verbs:
  1065. - update
  1066. - apiGroups:
  1067. - ""
  1068. resources:
  1069. - replicationcontrollers/finalizers
  1070. verbs:
  1071. - update
  1072. - apiGroups:
  1073. - ""
  1074. resources:
  1075. - pods
  1076. verbs:
  1077. - create
  1078. - delete
  1079. - list
  1080. - patch
  1081. - watch
  1082. - apiGroups:
  1083. - ""
  1084. - events.k8s.io
  1085. resources:
  1086. - events
  1087. verbs:
  1088. - create
  1089. - patch
  1090. - update
  1091. - apiVersion: rbac.authorization.k8s.io/v1
  1092. kind: ClusterRole
  1093. metadata:
  1094. annotations:
  1095. rbac.authorization.kubernetes.io/autoupdate: "true"
  1096. creationTimestamp: null
  1097. labels:
  1098. kubernetes.io/bootstrapping: rbac-defaults
  1099. name: system:controller:resourcequota-controller
  1100. rules:
  1101. - apiGroups:
  1102. - '*'
  1103. resources:
  1104. - '*'
  1105. verbs:
  1106. - list
  1107. - watch
  1108. - apiGroups:
  1109. - ""
  1110. resources:
  1111. - resourcequotas/status
  1112. verbs:
  1113. - update
  1114. - apiGroups:
  1115. - ""
  1116. - events.k8s.io
  1117. resources:
  1118. - events
  1119. verbs:
  1120. - create
  1121. - patch
  1122. - update
  1123. - apiVersion: rbac.authorization.k8s.io/v1
  1124. kind: ClusterRole
  1125. metadata:
  1126. annotations:
  1127. rbac.authorization.kubernetes.io/autoupdate: "true"
  1128. creationTimestamp: null
  1129. labels:
  1130. kubernetes.io/bootstrapping: rbac-defaults
  1131. name: system:controller:route-controller
  1132. rules:
  1133. - apiGroups:
  1134. - ""
  1135. resources:
  1136. - nodes
  1137. verbs:
  1138. - list
  1139. - watch
  1140. - apiGroups:
  1141. - ""
  1142. resources:
  1143. - nodes/status
  1144. verbs:
  1145. - patch
  1146. - apiGroups:
  1147. - ""
  1148. - events.k8s.io
  1149. resources:
  1150. - events
  1151. verbs:
  1152. - create
  1153. - patch
  1154. - update
  1155. - apiVersion: rbac.authorization.k8s.io/v1
  1156. kind: ClusterRole
  1157. metadata:
  1158. annotations:
  1159. rbac.authorization.kubernetes.io/autoupdate: "true"
  1160. creationTimestamp: null
  1161. labels:
  1162. kubernetes.io/bootstrapping: rbac-defaults
  1163. name: system:controller:service-account-controller
  1164. rules:
  1165. - apiGroups:
  1166. - ""
  1167. resources:
  1168. - serviceaccounts
  1169. verbs:
  1170. - create
  1171. - apiGroups:
  1172. - ""
  1173. - events.k8s.io
  1174. resources:
  1175. - events
  1176. verbs:
  1177. - create
  1178. - patch
  1179. - update
  1180. - apiVersion: rbac.authorization.k8s.io/v1
  1181. kind: ClusterRole
  1182. metadata:
  1183. annotations:
  1184. rbac.authorization.kubernetes.io/autoupdate: "true"
  1185. creationTimestamp: null
  1186. labels:
  1187. kubernetes.io/bootstrapping: rbac-defaults
  1188. name: system:controller:service-controller
  1189. rules:
  1190. - apiGroups:
  1191. - ""
  1192. resources:
  1193. - services
  1194. verbs:
  1195. - get
  1196. - list
  1197. - watch
  1198. - apiGroups:
  1199. - ""
  1200. resources:
  1201. - services/status
  1202. verbs:
  1203. - patch
  1204. - update
  1205. - apiGroups:
  1206. - ""
  1207. resources:
  1208. - nodes
  1209. verbs:
  1210. - list
  1211. - watch
  1212. - apiGroups:
  1213. - ""
  1214. - events.k8s.io
  1215. resources:
  1216. - events
  1217. verbs:
  1218. - create
  1219. - patch
  1220. - update
  1221. - apiVersion: rbac.authorization.k8s.io/v1
  1222. kind: ClusterRole
  1223. metadata:
  1224. annotations:
  1225. rbac.authorization.kubernetes.io/autoupdate: "true"
  1226. creationTimestamp: null
  1227. labels:
  1228. kubernetes.io/bootstrapping: rbac-defaults
  1229. name: system:controller:statefulset-controller
  1230. rules:
  1231. - apiGroups:
  1232. - ""
  1233. resources:
  1234. - pods
  1235. verbs:
  1236. - list
  1237. - watch
  1238. - apiGroups:
  1239. - apps
  1240. resources:
  1241. - statefulsets
  1242. verbs:
  1243. - get
  1244. - list
  1245. - watch
  1246. - apiGroups:
  1247. - apps
  1248. resources:
  1249. - statefulsets/status
  1250. verbs:
  1251. - update
  1252. - apiGroups:
  1253. - apps
  1254. resources:
  1255. - statefulsets/finalizers
  1256. verbs:
  1257. - update
  1258. - apiGroups:
  1259. - ""
  1260. resources:
  1261. - pods
  1262. verbs:
  1263. - create
  1264. - delete
  1265. - get
  1266. - patch
  1267. - update
  1268. - apiGroups:
  1269. - apps
  1270. resources:
  1271. - controllerrevisions
  1272. verbs:
  1273. - create
  1274. - delete
  1275. - get
  1276. - list
  1277. - patch
  1278. - update
  1279. - watch
  1280. - apiGroups:
  1281. - ""
  1282. resources:
  1283. - persistentvolumeclaims
  1284. verbs:
  1285. - create
  1286. - get
  1287. - apiGroups:
  1288. - ""
  1289. - events.k8s.io
  1290. resources:
  1291. - events
  1292. verbs:
  1293. - create
  1294. - patch
  1295. - update
  1296. - apiVersion: rbac.authorization.k8s.io/v1
  1297. kind: ClusterRole
  1298. metadata:
  1299. annotations:
  1300. rbac.authorization.kubernetes.io/autoupdate: "true"
  1301. creationTimestamp: null
  1302. labels:
  1303. kubernetes.io/bootstrapping: rbac-defaults
  1304. name: system:controller:ttl-controller
  1305. rules:
  1306. - apiGroups:
  1307. - ""
  1308. resources:
  1309. - nodes
  1310. verbs:
  1311. - list
  1312. - patch
  1313. - update
  1314. - watch
  1315. - apiGroups:
  1316. - ""
  1317. - events.k8s.io
  1318. resources:
  1319. - events
  1320. verbs:
  1321. - create
  1322. - patch
  1323. - update
  1324. kind: List
  1325. metadata: {}