@@ -4,7 +4,7 @@ apiVersion: rbac.authorization.k8s.io/v1
44metadata :
55 name : citrix-node-controller
66rules :
7- - apiGroups : [""]
7+ - apiGroups : ["* "]
88 resources : ["configmaps", "pods"]
99 verbs : ["get", "list", "watch", "create", "patch", "delete", "update"]
1010 - apiGroups : ["*"]
@@ -37,13 +37,47 @@ roleRef:
3737subjects :
3838- kind : ServiceAccount
3939 name : citrix-node-controller
40- namespace : citrix-system
40+ namespace : default
4141---
4242apiVersion : v1
4343kind : ServiceAccount
4444metadata :
4545 name : citrix-node-controller
46- namespace : citrix-system
46+ namespace : default
47+ ---
48+ kind : ClusterRole
49+ apiVersion : rbac.authorization.k8s.io/v1
50+ metadata :
51+ name : kube-cnc-router
52+ rules :
53+ - apiGroups : ["*"]
54+ resources : ["configmaps"]
55+ verbs : ["get", "list", "watch", "create", "patch", "delete", "update"]
56+ - apiGroups : [""]
57+ resources : ["configmaps"]
58+ verbs : ["get", "list", "watch", "create", "patch", "delete", "update"]
59+ - apiGroups : ["crd.projectcalico.org"]
60+ resources : ["ipamblocks"]
61+ verbs : ["get", "list"]
62+ ---
63+ kind : ClusterRoleBinding
64+ apiVersion : rbac.authorization.k8s.io/v1
65+ metadata :
66+ name : kube-cnc-router
67+ roleRef :
68+ apiGroup : rbac.authorization.k8s.io
69+ kind : ClusterRole
70+ name : kube-cnc-router
71+ subjects :
72+ - kind : ServiceAccount
73+ name : kube-cnc-router
74+ namespace : default
75+ ---
76+ apiVersion : v1
77+ kind : ServiceAccount
78+ metadata :
79+ name : kube-cnc-router
80+ namespace : default
4781---
4882apiVersion : apps/v1 # for k8s versions before 1.9.0 use apps/v1beta2 and before 1.8.0 use extensions/v1beta1
4983kind : Deployment
0 commit comments