|
@@ -4,22 +4,23 @@ metadata:
|
|
|
name: service-catalog
|
|
|
objects:
|
|
|
|
|
|
-- kind: ClusterRole
|
|
|
- apiVersion: v1
|
|
|
+- apiVersion: authorization.openshift.io/v1
|
|
|
+ kind: ClusterRole
|
|
|
metadata:
|
|
|
name: servicecatalog-serviceclass-viewer
|
|
|
rules:
|
|
|
- apiGroups:
|
|
|
- servicecatalog.k8s.io
|
|
|
resources:
|
|
|
- - serviceclasses
|
|
|
+ - clusterserviceclasses
|
|
|
+ - clusterserviceplans
|
|
|
verbs:
|
|
|
- list
|
|
|
- watch
|
|
|
- get
|
|
|
|
|
|
-- kind: ClusterRoleBinding
|
|
|
- apiVersion: v1
|
|
|
+- apiVersion: authorization.openshift.io/v1
|
|
|
+ kind: ClusterRoleBinding
|
|
|
metadata:
|
|
|
name: servicecatalog-serviceclass-viewer-binding
|
|
|
roleRef:
|
|
@@ -37,8 +38,8 @@ objects:
|
|
|
metadata:
|
|
|
name: service-catalog-apiserver
|
|
|
|
|
|
-- kind: ClusterRole
|
|
|
- apiVersion: v1
|
|
|
+- apiVersion: authorization.openshift.io/v1
|
|
|
+ kind: ClusterRole
|
|
|
metadata:
|
|
|
name: sar-creator
|
|
|
rules:
|
|
@@ -49,17 +50,19 @@ objects:
|
|
|
verbs:
|
|
|
- create
|
|
|
|
|
|
-- kind: ClusterRoleBinding
|
|
|
- apiVersion: v1
|
|
|
+- apiVersion: authorization.openshift.io/v1
|
|
|
+ kind: ClusterRoleBinding
|
|
|
metadata:
|
|
|
name: service-catalog-sar-creator-binding
|
|
|
roleRef:
|
|
|
name: sar-creator
|
|
|
- userNames:
|
|
|
- - system:serviceaccount:kube-service-catalog:service-catalog-apiserver
|
|
|
+ subjects:
|
|
|
+ - kind: ServiceAccount
|
|
|
+ name: service-catalog-apiserver
|
|
|
+ namespace: kube-service-catalog
|
|
|
|
|
|
-- kind: ClusterRole
|
|
|
- apiVersion: v1
|
|
|
+- apiVersion: authorization.openshift.io/v1
|
|
|
+ kind: ClusterRole
|
|
|
metadata:
|
|
|
name: namespace-viewer
|
|
|
rules:
|
|
@@ -72,26 +75,30 @@ objects:
|
|
|
- watch
|
|
|
- get
|
|
|
|
|
|
-- kind: ClusterRoleBinding
|
|
|
- apiVersion: v1
|
|
|
+- apiVersion: authorization.openshift.io/v1
|
|
|
+ kind: ClusterRoleBinding
|
|
|
metadata:
|
|
|
name: service-catalog-namespace-viewer-binding
|
|
|
roleRef:
|
|
|
name: namespace-viewer
|
|
|
- userNames:
|
|
|
- - system:serviceaccount:kube-service-catalog:service-catalog-apiserver
|
|
|
+ subjects:
|
|
|
+ - kind: ServiceAccount
|
|
|
+ name: service-catalog-apiserver
|
|
|
+ namespace: kube-service-catalog
|
|
|
|
|
|
-- kind: ClusterRoleBinding
|
|
|
- apiVersion: v1
|
|
|
+- apiVersion: authorization.openshift.io/v1
|
|
|
+ kind: ClusterRoleBinding
|
|
|
metadata:
|
|
|
name: service-catalog-controller-namespace-viewer-binding
|
|
|
roleRef:
|
|
|
name: namespace-viewer
|
|
|
- userNames:
|
|
|
- - system:serviceaccount:kube-service-catalog:service-catalog-controller
|
|
|
+ subjects:
|
|
|
+ - kind: ServiceAccount
|
|
|
+ name: service-catalog-controller
|
|
|
+ namespace: kube-service-catalog
|
|
|
|
|
|
-- kind: ClusterRole
|
|
|
- apiVersion: v1
|
|
|
+- apiVersion: authorization.openshift.io/v1
|
|
|
+ kind: ClusterRole
|
|
|
metadata:
|
|
|
name: service-catalog-controller
|
|
|
rules:
|
|
@@ -102,6 +109,7 @@ objects:
|
|
|
verbs:
|
|
|
- create
|
|
|
- update
|
|
|
+ - patch
|
|
|
- delete
|
|
|
- get
|
|
|
- list
|
|
@@ -109,19 +117,22 @@ objects:
|
|
|
- apiGroups:
|
|
|
- servicecatalog.k8s.io
|
|
|
resources:
|
|
|
- - brokers/status
|
|
|
- - instances/status
|
|
|
- - bindings/status
|
|
|
+ - clusterservicebrokers/status
|
|
|
+ - serviceinstances/status
|
|
|
+ - servicebindings/status
|
|
|
+ - servicebindings/finalizers
|
|
|
+ - serviceinstances/reference
|
|
|
verbs:
|
|
|
- update
|
|
|
- apiGroups:
|
|
|
- servicecatalog.k8s.io
|
|
|
resources:
|
|
|
- - brokers
|
|
|
- - instances
|
|
|
- - bindings
|
|
|
+ - clusterservicebrokers
|
|
|
+ - serviceinstances
|
|
|
+ - servicebindings
|
|
|
verbs:
|
|
|
- list
|
|
|
+ - get
|
|
|
- watch
|
|
|
- apiGroups:
|
|
|
- ""
|
|
@@ -133,7 +144,8 @@ objects:
|
|
|
- apiGroups:
|
|
|
- servicecatalog.k8s.io
|
|
|
resources:
|
|
|
- - serviceclasses
|
|
|
+ - clusterserviceclasses
|
|
|
+ - clusterserviceplans
|
|
|
verbs:
|
|
|
- create
|
|
|
- delete
|
|
@@ -154,17 +166,19 @@ objects:
|
|
|
- list
|
|
|
- watch
|
|
|
|
|
|
-- kind: ClusterRoleBinding
|
|
|
- apiVersion: v1
|
|
|
+- apiVersion: authorization.openshift.io/v1
|
|
|
+ kind: ClusterRoleBinding
|
|
|
metadata:
|
|
|
name: service-catalog-controller-binding
|
|
|
roleRef:
|
|
|
name: service-catalog-controller
|
|
|
- userNames:
|
|
|
- - system:serviceaccount:kube-service-catalog:service-catalog-controller
|
|
|
-
|
|
|
-- kind: Role
|
|
|
- apiVersion: v1
|
|
|
+ subjects:
|
|
|
+ - kind: ServiceAccount
|
|
|
+ name: service-catalog-controller
|
|
|
+ namespace: kube-service-catalog
|
|
|
+
|
|
|
+- apiVersion: authorization.openshift.io/v1
|
|
|
+ kind: Role
|
|
|
metadata:
|
|
|
name: endpoint-accessor
|
|
|
rules:
|
|
@@ -179,21 +193,25 @@ objects:
|
|
|
- create
|
|
|
- update
|
|
|
|
|
|
-- kind: RoleBinding
|
|
|
- apiVersion: v1
|
|
|
+- apiVersion: authorization.openshift.io/v1
|
|
|
+ kind: RoleBinding
|
|
|
metadata:
|
|
|
- name: endpoint-accessor-binding
|
|
|
+ name: endpointer-accessor-binding
|
|
|
roleRef:
|
|
|
name: endpoint-accessor
|
|
|
namespace: kube-service-catalog
|
|
|
- userNames:
|
|
|
- - system:serviceaccount:kube-service-catalog:service-catalog-controller
|
|
|
+ subjects:
|
|
|
+ - kind: ServiceAccount
|
|
|
+ namespace: kube-service-catalog
|
|
|
+ name: service-catalog-controller
|
|
|
|
|
|
-- kind: ClusterRoleBinding
|
|
|
- apiVersion: v1
|
|
|
+- apiVersion: authorization.openshift.io/v1
|
|
|
+ kind: ClusterRoleBinding
|
|
|
metadata:
|
|
|
name: system:auth-delegator-binding
|
|
|
roleRef:
|
|
|
name: system:auth-delegator
|
|
|
- userNames:
|
|
|
- - system:serviceaccount:kube-service-catalog:service-catalog-apiserver
|
|
|
+ subjects:
|
|
|
+ - kind: ServiceAccount
|
|
|
+ name: service-catalog-apiserver
|
|
|
+ namespace: kube-service-catalog
|