kubelet-binding.yaml 782 B

123456789101112131415161718192021222324252627282930
  1. # This is required so that old clusters don't remove required bindings for 1.5
  2. # kubelets to function.
  3. apiVersion: rbac.authorization.k8s.io/v1
  4. kind: ClusterRoleBinding
  5. metadata:
  6. name: kubelet-cluster-admin
  7. labels:
  8. addonmanager.kubernetes.io/mode: EnsureExists
  9. roleRef:
  10. apiGroup: rbac.authorization.k8s.io
  11. kind: ClusterRole
  12. name: system:node
  13. subjects: []
  14. ---
  15. # This is required so that new clusters still have bootstrap permissions
  16. apiVersion: rbac.authorization.k8s.io/v1
  17. kind: ClusterRoleBinding
  18. metadata:
  19. name: kubelet-bootstrap
  20. labels:
  21. addonmanager.kubernetes.io/mode: Reconcile
  22. roleRef:
  23. apiGroup: rbac.authorization.k8s.io
  24. kind: ClusterRole
  25. name: system:node-bootstrapper
  26. subjects:
  27. - apiGroup: rbac.authorization.k8s.io
  28. kind: User
  29. name: kubelet