kubesystem_roles_bindings.yml 865 B

1234567891011121314151617181920212223242526272829303132333435363738
  1. apiVersion: v1
  2. kind: Template
  3. metadata:
  4. name: kube-system-service-catalog
  5. objects:
  6. - kind: Role
  7. apiVersion: v1
  8. metadata:
  9. name: extension-apiserver-authentication-reader
  10. namespace: ${KUBE_SYSTEM_NAMESPACE}
  11. rules:
  12. - apiGroups:
  13. - ""
  14. resourceNames:
  15. - extension-apiserver-authentication
  16. resources:
  17. - configmaps
  18. verbs:
  19. - get
  20. - kind: RoleBinding
  21. apiVersion: v1
  22. metadata:
  23. name: extension-apiserver-authentication-reader-binding
  24. namespace: ${KUBE_SYSTEM_NAMESPACE}
  25. roleRef:
  26. name: extension-apiserver-authentication-reader
  27. namespace: kube-system
  28. userNames:
  29. - system:serviceaccount:kube-service-catalog:service-catalog-apiserver
  30. parameters:
  31. - description: Do not change this value.
  32. displayName: Name of the kube-system namespace
  33. name: KUBE_SYSTEM_NAMESPACE
  34. required: true
  35. value: kube-system