0
|
1 apiVersion: v1
|
|
2 kind: ServiceAccount
|
|
3 metadata:
|
|
4 labels:
|
|
5 app.kubernetes.io/name: pomerium
|
|
6 name: pomerium-controller
|
|
7 namespace: pomerium
|
|
8 ---
|
|
9 apiVersion: v1
|
|
10 kind: ServiceAccount
|
|
11 metadata:
|
|
12 labels:
|
|
13 app.kubernetes.io/name: pomerium
|
|
14 name: pomerium-gen-secrets
|
|
15 namespace: pomerium
|
|
16 ---
|
|
17 apiVersion: rbac.authorization.k8s.io/v1
|
|
18 kind: ClusterRole
|
|
19 metadata:
|
|
20 labels:
|
|
21 app.kubernetes.io/name: pomerium
|
|
22 name: pomerium-controller
|
|
23 rules:
|
|
24 - apiGroups:
|
|
25 - ""
|
|
26 resources:
|
|
27 - services
|
|
28 - endpoints
|
|
29 - secrets
|
|
30 verbs:
|
|
31 - get
|
|
32 - list
|
|
33 - watch
|
|
34 - apiGroups:
|
|
35 - ""
|
|
36 resources:
|
|
37 - services/status
|
|
38 - secrets/status
|
|
39 - endpoints/status
|
|
40 verbs:
|
|
41 - get
|
|
42 - apiGroups:
|
|
43 - networking.k8s.io
|
|
44 resources:
|
|
45 - ingresses
|
|
46 - ingressclasses
|
|
47 verbs:
|
|
48 - get
|
|
49 - list
|
|
50 - watch
|
|
51 - apiGroups:
|
|
52 - networking.k8s.io
|
|
53 resources:
|
|
54 - ingresses/status
|
|
55 verbs:
|
|
56 - get
|
|
57 - patch
|
|
58 - update
|
|
59 - apiGroups:
|
|
60 - ingress.pomerium.io
|
|
61 resources:
|
|
62 - pomerium
|
|
63 verbs:
|
|
64 - get
|
|
65 - list
|
|
66 - watch
|
|
67 - apiGroups:
|
|
68 - ingress.pomerium.io
|
|
69 resources:
|
|
70 - pomerium/status
|
|
71 verbs:
|
|
72 - get
|
|
73 - update
|
|
74 - patch
|
|
75 - apiGroups:
|
|
76 - ""
|
|
77 resources:
|
|
78 - events
|
|
79 verbs:
|
|
80 - create
|
|
81 - patch
|
|
82 ---
|
|
83 apiVersion: rbac.authorization.k8s.io/v1
|
|
84 kind: ClusterRole
|
|
85 metadata:
|
|
86 labels:
|
|
87 app.kubernetes.io/name: pomerium
|
|
88 name: pomerium-gen-secrets
|
|
89 rules:
|
|
90 - apiGroups:
|
|
91 - ""
|
|
92 resources:
|
|
93 - secrets
|
|
94 verbs:
|
|
95 - create
|
|
96 ---
|
|
97 apiVersion: rbac.authorization.k8s.io/v1
|
|
98 kind: ClusterRoleBinding
|
|
99 metadata:
|
|
100 labels:
|
|
101 app.kubernetes.io/name: pomerium
|
|
102 name: pomerium-controller
|
|
103 roleRef:
|
|
104 apiGroup: rbac.authorization.k8s.io
|
|
105 kind: ClusterRole
|
|
106 name: pomerium-controller
|
|
107 subjects:
|
|
108 - kind: ServiceAccount
|
|
109 name: pomerium-controller
|
|
110 namespace: pomerium
|
|
111 ---
|
|
112 apiVersion: rbac.authorization.k8s.io/v1
|
|
113 kind: ClusterRoleBinding
|
|
114 metadata:
|
|
115 labels:
|
|
116 app.kubernetes.io/name: pomerium
|
|
117 name: pomerium-gen-secrets
|
|
118 roleRef:
|
|
119 apiGroup: rbac.authorization.k8s.io
|
|
120 kind: ClusterRole
|
|
121 name: pomerium-gen-secrets
|
|
122 subjects:
|
|
123 - kind: ServiceAccount
|
|
124 name: pomerium-gen-secrets
|
|
125 namespace: pomerium |