From 83deecb9e9a02c8e2252cea864a33fb583c9c58b Mon Sep 17 00:00:00 2001
From: jwfang <54740235@qq.com>
Date: Mon, 10 Jul 2017 19:05:42 +0800
Subject: [PATCH] Revert "no need to patch system:kube-dns"

This reverts commit c2ea8c588aa5c3879f402811d3599a7bb3ccab24.
---
 roles/kubernetes-apps/ansible/tasks/main.yml | 17 +++++++++++++++++
 1 file changed, 17 insertions(+)

diff --git a/roles/kubernetes-apps/ansible/tasks/main.yml b/roles/kubernetes-apps/ansible/tasks/main.yml
index 421cdec79..00a1fd74d 100644
--- a/roles/kubernetes-apps/ansible/tasks/main.yml
+++ b/roles/kubernetes-apps/ansible/tasks/main.yml
@@ -26,6 +26,23 @@
     - rbac_enabled or item.type not in kubedns_rbac_resources
   tags: dnsmasq
 
+# see https://github.com/kubernetes/kubernetes/issues/45084
+# TODO: this is only needed for "old" kube-dns
+- name: Kubernetes Apps | Patch system:kube-dns ClusterRole
+  command: >
+    {{bin_dir}}/kubectl patch clusterrole system:kube-dns
+    --patch='{
+               "rules": [
+                 {
+                   "apiGroups" : [""],
+                   "resources" : ["endpoints", "services"],
+                   "verbs": ["list", "watch", "get"]
+                 }
+               ]
+             }'
+  when: dns_mode != 'none' and inventory_hostname == groups['kube-master'][0] and rbac_enabled
+  tags: dnsmasq
+
 - name: Kubernetes Apps | Start Resources
   kube:
     name: "{{item.item.name}}"
-- 
GitLab