Skip to content
Snippets Groups Projects
Commit 80cfeea9 authored by Erwan Miran's avatar Erwan Miran
Browse files

psp, roles and rbs for PodSecurityPolicy when podsecuritypolicy_enabled is true

parent 4eea7f7e
No related branches found
No related tags found
No related merge requests found
...@@ -11,3 +11,11 @@ rules: ...@@ -11,3 +11,11 @@ rules:
- nodes - nodes
verbs: verbs:
- get - get
- apiGroups:
- policy
resourceNames:
- privileged
resources:
- podsecuritypolicies
verbs:
- use
...@@ -78,3 +78,11 @@ rules: ...@@ -78,3 +78,11 @@ rules:
verbs: verbs:
- get - get
- list - list
- apiGroups:
- policy
resourceNames:
- privileged
resources:
- podsecuritypolicies
verbs:
- use
...@@ -24,3 +24,11 @@ rules: ...@@ -24,3 +24,11 @@ rules:
- nodes/status - nodes/status
verbs: verbs:
- patch - patch
- apiGroups:
- policy
resourceNames:
- privileged
resources:
- podsecuritypolicies
verbs:
- use
...@@ -64,3 +64,11 @@ rules: ...@@ -64,3 +64,11 @@ rules:
- ciliumendpoints/status - ciliumendpoints/status
verbs: verbs:
- "*" - "*"
- apiGroups:
- policy
resourceNames:
- privileged
resources:
- podsecuritypolicies
verbs:
- use
...@@ -16,3 +16,11 @@ rules: ...@@ -16,3 +16,11 @@ rules:
- watch - watch
- list - list
- update - update
- apiGroups:
- policy
resourceNames:
- privileged
resources:
- podsecuritypolicies
verbs:
- use
...@@ -19,3 +19,11 @@ rules: ...@@ -19,3 +19,11 @@ rules:
- list - list
- update - update
- get - get
- apiGroups:
- policy
resourceNames:
- privileged
resources:
- podsecuritypolicies
verbs:
- use
...@@ -29,6 +29,14 @@ rules: ...@@ -29,6 +29,14 @@ rules:
- nodes/status - nodes/status
verbs: verbs:
- patch - patch
- apiGroups:
- policy
resourceNames:
- privileged
resources:
- podsecuritypolicies
verbs:
- use
--- ---
kind: ClusterRoleBinding kind: ClusterRoleBinding
apiVersion: rbac.authorization.k8s.io/v1beta1 apiVersion: rbac.authorization.k8s.io/v1beta1
......
...@@ -41,6 +41,14 @@ items: ...@@ -41,6 +41,14 @@ items:
verbs: verbs:
- patch - patch
- update - update
- apiGroups:
- policy
resourceNames:
- privileged
resources:
- podsecuritypolicies
verbs:
- use
- apiVersion: rbac.authorization.k8s.io/v1beta1 - apiVersion: rbac.authorization.k8s.io/v1beta1
kind: ClusterRoleBinding kind: ClusterRoleBinding
metadata: metadata:
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment