diff options
Diffstat (limited to 'docs/container_groups')
-rw-r--r-- | docs/container_groups/service-account.yml | 31 |
1 files changed, 18 insertions, 13 deletions
diff --git a/docs/container_groups/service-account.yml b/docs/container_groups/service-account.yml index 20e4e7c0fa..37a215b154 100644 --- a/docs/container_groups/service-account.yml +++ b/docs/container_groups/service-account.yml @@ -13,30 +13,35 @@ apiVersion: v1 kind: ServiceAccount metadata: - name: awx - + name: containergroup-service-account + namespace: containergroup-namespace --- -apiVersion: rbac.authorization.k8s.io/v1 kind: Role +apiVersion: rbac.authorization.k8s.io/v1 metadata: - name: pod-manager + name: role-containergroup-service-account + namespace: containergroup-namespace rules: - - apiGroups: [""] # "" indicates the core API group + - apiGroups: [""] resources: ["pods"] verbs: ["get", "list", "watch", "create", "update", "patch", "delete"] - apiGroups: [""] - resources: ["pods/exec"] - verbs: ["create"] - + resources: ["pods/log"] + verbs: ["get", "list", "watch", "create", "update", "patch", "delete"] + - apiGroups: [""] + resources: ["pods/attach"] + verbs: ["get", "list", "watch", "create", "update", "patch", "delete"] --- kind: RoleBinding -apiVersion: rbac.authorization.k8s.io/v1beta1 +apiVersion: rbac.authorization.k8s.io/v1 metadata: - name: awx-pod-manager + name: role-containergroup-service-account-binding + namespace: containergroup-namespace subjects: - kind: ServiceAccount - name: awx + name: containergroup-service-account + namespace: containergroup-namespace roleRef: - apiGroup: rbac.authorization.k8s.io kind: Role - name: pod-manager + name: role-containergroup-service-account + apiGroup: rbac.authorization.k8s.io |