rbac.yaml 700 B

1234567891011121314151617181920212223242526272829303132333435363738394041424344
  1. apiVersion: v1
  2. kind: ServiceAccount
  3. metadata:
  4. name: proxy-kubeconfig-generator
  5. ---
  6. kind: Role
  7. apiVersion: rbac.authorization.k8s.io/v1
  8. metadata:
  9. name: proxy-kubeconfig-generator
  10. rules:
  11. - apiGroups:
  12. - ""
  13. resources:
  14. - serviceaccounts
  15. - serviceaccounts/token
  16. verbs:
  17. - create
  18. - delete
  19. - get
  20. - list
  21. - patch
  22. - update
  23. - watch
  24. - apiGroups:
  25. - ""
  26. resources:
  27. - secrets
  28. verbs:
  29. - create
  30. - list
  31. - get
  32. ---
  33. apiVersion: rbac.authorization.k8s.io/v1
  34. kind: RoleBinding
  35. metadata:
  36. name: proxy-kubeconfig-generator
  37. roleRef:
  38. apiGroup: rbac.authorization.k8s.io
  39. kind: Role
  40. name: proxy-kubeconfig-generator
  41. subjects:
  42. - kind: ServiceAccount
  43. name: proxy-kubeconfig-generator