Remove endpoints (old leader election) related RBAC from kube-controller-manager ClusterRole
This commit is contained in:
		| @@ -432,9 +432,6 @@ func ClusterRoles() []rbacv1.ClusterRole { | |||||||
| 				// Needed for leader election. | 				// Needed for leader election. | ||||||
| 				rbacv1helpers.NewRule("create").Groups(coordinationGroup).Resources("leases").RuleOrDie(), | 				rbacv1helpers.NewRule("create").Groups(coordinationGroup).Resources("leases").RuleOrDie(), | ||||||
| 				rbacv1helpers.NewRule("get", "update").Groups(coordinationGroup).Resources("leases").Names("kube-controller-manager").RuleOrDie(), | 				rbacv1helpers.NewRule("get", "update").Groups(coordinationGroup).Resources("leases").Names("kube-controller-manager").RuleOrDie(), | ||||||
| 				// TODO: Remove once we fully migrate to lease in leader-election. |  | ||||||
| 				rbacv1helpers.NewRule("create").Groups(legacyGroup).Resources("endpoints").RuleOrDie(), |  | ||||||
| 				rbacv1helpers.NewRule("get", "update").Groups(legacyGroup).Resources("endpoints").Names("kube-controller-manager").RuleOrDie(), |  | ||||||
| 				// Fundamental resources. | 				// Fundamental resources. | ||||||
| 				rbacv1helpers.NewRule("create").Groups(legacyGroup).Resources("secrets", "serviceaccounts").RuleOrDie(), | 				rbacv1helpers.NewRule("create").Groups(legacyGroup).Resources("secrets", "serviceaccounts").RuleOrDie(), | ||||||
| 				rbacv1helpers.NewRule("delete").Groups(legacyGroup).Resources("secrets").RuleOrDie(), | 				rbacv1helpers.NewRule("delete").Groups(legacyGroup).Resources("secrets").RuleOrDie(), | ||||||
|   | |||||||
| @@ -636,21 +636,6 @@ items: | |||||||
|     verbs: |     verbs: | ||||||
|     - get |     - get | ||||||
|     - update |     - update | ||||||
|   - apiGroups: |  | ||||||
|     - "" |  | ||||||
|     resources: |  | ||||||
|     - endpoints |  | ||||||
|     verbs: |  | ||||||
|     - create |  | ||||||
|   - apiGroups: |  | ||||||
|     - "" |  | ||||||
|     resourceNames: |  | ||||||
|     - kube-controller-manager |  | ||||||
|     resources: |  | ||||||
|     - endpoints |  | ||||||
|     verbs: |  | ||||||
|     - get |  | ||||||
|     - update |  | ||||||
|   - apiGroups: |   - apiGroups: | ||||||
|     - "" |     - "" | ||||||
|     resources: |     resources: | ||||||
|   | |||||||
		Reference in New Issue
	
	Block a user
	 ialidzhikov
					ialidzhikov