|
@@ -0,0 +1,26 @@
|
|
|
+# Create the clusterrole:
|
|
|
+# $ kubectl create -f kube-flannel-rbac.yml
|
|
|
+# Bind the flannel serviceaccount to the flannel clusterrole:
|
|
|
+# $ kubectl create clusterrolebinding flannel --clusterrole=flannel --serviceaccount=kube-system:flannel
|
|
|
+# Create the pod using the same namespace used by the flannel serviceaccount:
|
|
|
+# $ kubectl create --namespace kube-system -f kube-flannel.yml
|
|
|
+---
|
|
|
+kind: ClusterRole
|
|
|
+apiVersion: rbac.authorization.k8s.io/v1beta1
|
|
|
+metadata:
|
|
|
+ name: flannel
|
|
|
+rules:
|
|
|
+ - apiGroups:
|
|
|
+ - ""
|
|
|
+ resources:
|
|
|
+ - pods
|
|
|
+ verbs:
|
|
|
+ - get
|
|
|
+ - apiGroups:
|
|
|
+ - ""
|
|
|
+ resources:
|
|
|
+ - nodes
|
|
|
+ verbs:
|
|
|
+ - list
|
|
|
+ - update
|
|
|
+ - watch
|