apiVersion: rbac.authorization.k8s.io/v1kind: ClusterRolemetadata:name: apigw-ingress-clusterrolerules:- apiGroups:- ""resources:- services- namespaces- endpoints- nodes- podsverbs:- get- list- watch- apiGroups:- appsresources:- deployments- replicasetsverbs:- get- list- watch- apiGroups:- ""resources:- configmaps- secretsverbs:- "*"- apiGroups:- extensionsresources:- ingresses- ingresses/statusverbs:- "*"- apiGroups:- ""resources:- eventsverbs:- create- patch- list- update- apiGroups:- apiextensions.k8s.ioresources:- customresourcedefinitionsverbs:- "*"- apiGroups:- cloud.tencent.comresources:- tkeserviceconfigsverbs:- "*"---apiVersion: v1kind: ServiceAccountmetadata:namespace: kube-systemname: apigw-ingress---apiVersion: rbac.authorization.k8s.io/v1kind: ClusterRoleBindingmetadata:name: apigw-ingress-clusterrole-bindingroleRef:apiGroup: rbac.authorization.k8s.iokind: ClusterRolename: apigw-ingress-clusterrolesubjects:- kind: ServiceAccountname: apigw-ingressnamespace: kube-system
文档反馈