X-Git-Url: https://gerrit.akraino.org/r/gitweb?a=blobdiff_plain;f=src%2Ffoundation%2Fscripts%2Fcni%2Fdanm%2Fintegration%2Fmanifests%2Fnetwatcher%2F0netwatcher_rbac.yaml;fp=src%2Ffoundation%2Fscripts%2Fcni%2Fdanm%2Fintegration%2Fmanifests%2Fnetwatcher%2F0netwatcher_rbac.yaml;h=28a8ac219db642f3495b5aa6072bc5566a84d547;hb=9bb5493922a305ff0491058a1ddffef00a3fe67c;hp=0000000000000000000000000000000000000000;hpb=a4546182269b01038a1e672cb16b081930bd11bb;p=iec.git diff --git a/src/foundation/scripts/cni/danm/integration/manifests/netwatcher/0netwatcher_rbac.yaml b/src/foundation/scripts/cni/danm/integration/manifests/netwatcher/0netwatcher_rbac.yaml new file mode 100644 index 0000000..28a8ac2 --- /dev/null +++ b/src/foundation/scripts/cni/danm/integration/manifests/netwatcher/0netwatcher_rbac.yaml @@ -0,0 +1,44 @@ +# yamllint disable rule:hyphens rule:commas rule:indentation +apiVersion: v1 +kind: ServiceAccount +metadata: + name: netwatcher + namespace: kube-system + labels: + kubernetes.io/cluster-service: "true" +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + labels: + kubernetes.io/bootstrapping: rbac-defaults + name: system:netwatcher +rules: +- apiGroups: + - "danm.k8s.io" + resources: + - danmnets + - clusternetworks + - tenantnetworks + verbs: + - get + - list + - watch + - update +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + annotations: + rbac.authorization.kubernetes.io/autoupdate: "true" + labels: + kubernetes.io/bootstrapping: rbac-defaults + name: system:netwatcher +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: system:netwatcher +subjects: +- kind: ServiceAccount + namespace: kube-system + name: netwatcher