Skip to content

Commit aa53cba

Browse files
committed
Add RBAC configurations to API server
1 parent 52c04e8 commit aa53cba

File tree

1 file changed

+4
-2
lines changed

1 file changed

+4
-2
lines changed

roles/k8s/templates/k8s-master.j2

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -156,8 +156,10 @@ coreos:
156156
--service-account-key-file=/opt/bin/kube-serviceaccount.key \
157157
--service-account-lookup=false \
158158
--basic-auth-file=/srv/kubernetes/basicauth.csv \
159-
--admission-control=NamespaceLifecycle,NamespaceAutoProvision,LimitRanger,SecurityContextDeny,ServiceAccount,ResourceQuota \
160-
--runtime-config=api/v1 \
159+
--admission-control=NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,ResourceQuota \
160+
--authorization-mode=RBAC \
161+
--authorization-rbac-super-user={{ k8s_username }} \
162+
--runtime-config=api/v1,rbac.authorization.k8s.io/v1alpha1 \
161163
--allow-privileged=true \
162164
--insecure-port=8080 \
163165
--secure-port=443 \

0 commit comments

Comments
 (0)