Skip to content

Commit f138372

Browse files
committed
Add more permissions
Signed-off-by: Vihang Mehta <vihang@pixielabs.ai>
1 parent ef896ba commit f138372

File tree

1 file changed

+61
-0
lines changed

1 file changed

+61
-0
lines changed

k8s/vizier/bootstrap/updater_role.yaml

Lines changed: 61 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -79,3 +79,64 @@ subjects:
7979
- kind: ServiceAccount
8080
name: pl-updater-service-account
8181
namespace: pl
82+
---
83+
apiVersion: rbac.authorization.k8s.io/v1
84+
kind: ClusterRole
85+
metadata:
86+
name: pl-updater-cluster-role
87+
rules:
88+
- apiGroups:
89+
- rbac.authorization.k8s.io
90+
resources:
91+
- clusterroles
92+
- clusterrolebindings
93+
verbs:
94+
- create
95+
- delete
96+
- get
97+
- list
98+
- patch
99+
- update
100+
- watch
101+
- apiGroups:
102+
- ""
103+
resources:
104+
- namespaces
105+
verbs:
106+
- get
107+
resourceNames:
108+
- kube-system
109+
- apiGroups:
110+
- ""
111+
resources:
112+
- nodes
113+
- pods
114+
- services
115+
- endpoints
116+
- namespaces
117+
verbs:
118+
- get
119+
- watch
120+
- list
121+
- apiGroups:
122+
- apps
123+
resources:
124+
- replicasets
125+
- deployments
126+
verbs:
127+
- get
128+
- watch
129+
- list
130+
---
131+
apiVersion: rbac.authorization.k8s.io/v1
132+
kind: ClusterRoleBinding
133+
metadata:
134+
name: pl-updater-cluster-binding
135+
roleRef:
136+
apiGroup: rbac.authorization.k8s.io
137+
kind: ClusterRole
138+
name: pl-updater-cluster-role
139+
subjects:
140+
- kind: ServiceAccount
141+
name: pl-updater-service-account
142+
namespace: pl

0 commit comments

Comments
 (0)