gce: split legacy kubelet node role binding and bootstrapper role binding

This commit is contained in:
Jordan Liggitt 2017-12-13 21:56:18 -05:00
parent bba84d785e
commit c4e63cb777
No known key found for this signature in database
GPG Key ID: 39928704103C7229

View File

@ -7,6 +7,20 @@ metadata:
labels:
kubernetes.io/cluster-service: "true"
addonmanager.kubernetes.io/mode: EnsureExists
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: system:node
subjects: []
---
# This is required so that new clusters still have bootstrap permissions
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: kubelet-bootstrap
labels:
kubernetes.io/cluster-service: "true"
addonmanager.kubernetes.io/mode: Reconcile
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole