Difference between revisions of "Kind: ClusterRole"
Jump to navigation
Jump to search
Line 10: | Line 10: | ||
resources: ["pods"] | resources: ["pods"] | ||
verbs: ["get", "list", "watch"] | verbs: ["get", "list", "watch"] | ||
+ | |||
+ | Ref: https://stackoverflow.com/a/53524535 | ||
+ | |||
+ | |||
+ | {{K8s RBAC}} |
Revision as of 16:23, 25 August 2022
kind: ClusterRole apiVersion: rbac.authorization.k8s.io/v1 metadata: namespace: '*' name: pod-reader rules: - apiGroups: ["extensions", "apps", ""] resources: ["pods"] verbs: ["get", "list", "watch"] Ref: https://stackoverflow.com/a/53524535
Kubernetes RBAC kubectl auth, kubectl auth can-i, kubectl auth reconcile
kubectl create [ role | clusterrole | clusterrolebinding
| rolebinding | serviceaccount ], groups:
, Kubernetes RBAC good practices, kube2iam
, K8s Cluster roles, rbac.authorization.k8s.io
, system:
Advertising: