kubesystem_roles_bindings.yml 967 B

12345678910111213141516171819202122232425262728293031323334353637383940
  1. apiVersion: v1
  2. kind: Template
  3. metadata:
  4. name: kube-system-service-catalog-role-bindings
  5. objects:
  6. - apiVersion: authorization.openshift.io/v1
  7. kind: Role
  8. metadata:
  9. name: extension-apiserver-authentication-reader
  10. namespace: ${KUBE_SYSTEM_NAMESPACE}
  11. rules:
  12. - apiGroups:
  13. - ""
  14. resourceNames:
  15. - extension-apiserver-authentication
  16. resources:
  17. - configmaps
  18. verbs:
  19. - get
  20. - apiVersion: authorization.openshift.io/v1
  21. kind: RoleBinding
  22. metadata:
  23. name: extension-apiserver-authentication-reader-binding
  24. namespace: ${KUBE_SYSTEM_NAMESPACE}
  25. roleRef:
  26. name: extension-apiserver-authentication-reader
  27. namespace: ${KUBE_SYSTEM_NAMESPACE}
  28. subjects:
  29. - kind: ServiceAccount
  30. name: service-catalog-apiserver
  31. namespace: kube-service-catalog
  32. parameters:
  33. - description: Do not change this value.
  34. displayName: Name of the kube-system namespace
  35. name: KUBE_SYSTEM_NAMESPACE
  36. required: true
  37. value: kube-system