persistent-volume-binder-role.yaml 572 B

123456789101112131415161718192021
  1. apiVersion: rbac.authorization.k8s.io/v1
  2. # The persistent volume binder creates recycler pods in the default namespace,
  3. # but the addon manager only creates namespaced objects in the kube-system
  4. # namespace, so this is a ClusterRole.
  5. kind: ClusterRole
  6. metadata:
  7. name: gce:podsecuritypolicy:persistent-volume-binder
  8. namespace: default
  9. labels:
  10. kubernetes.io/cluster-service: "true"
  11. addonmanager.kubernetes.io/mode: Reconcile
  12. rules:
  13. - apiGroups:
  14. - policy
  15. resourceNames:
  16. - gce.persistent-volume-binder
  17. resources:
  18. - podsecuritypolicies
  19. verbs:
  20. - use