소스 검색

Merge pull request #614 from GheRivero/rbac_binding

Simplify rbac creation process
Tom Denham 8 년 전
부모
커밋
699027228c
1개의 변경된 파일14개의 추가작업 그리고 3개의 파일을 삭제
  1. 14 3
      Documentation/kube-flannel-rbac.yml

+ 14 - 3
Documentation/kube-flannel-rbac.yml

@@ -1,7 +1,5 @@
-# Create the clusterrole:
+# Create the clusterrole and clusterrolebinding:
 # $ kubectl create -f kube-flannel-rbac.yml
-# Bind the flannel serviceaccount to the flannel clusterrole:
-# $ kubectl create clusterrolebinding flannel --clusterrole=flannel --serviceaccount=kube-system:flannel
 # Create the pod using the same namespace used by the flannel serviceaccount:
 # $ kubectl create --namespace kube-system -f kube-flannel.yml
 ---
@@ -24,3 +22,16 @@ rules:
       - list
       - update
       - watch
+---
+kind: ClusterRoleBinding
+apiVersion: rbac.authorization.k8s.io/v1beta1
+metadata:
+  name: flannel
+roleRef:
+  apiGroup: rbac.authorization.k8s.io
+  kind: ClusterRole
+  name: flannel
+subjects:
+- kind: ServiceAccount
+  name: flannel
+  namespace: kube-system