Cheatsheet 11 - Access Control
Namespace-Manifest Beispiel
---
apiVersion: v1
kind: Namespace
metadata:
name: test
Namespace in einer Resource definieren
---
apiVersion: apps/v1
kind: Deployment # Auch Pod, Job oder jegliche weitere Resource.
metadata:
name: my-resource
namespace: my-namespace
spec:
[...]
ServiceAccount-Manifest Beispiel
---
apiVersion: v1
kind: ServiceAccount
metadata:
name: my-service-account
namespace: my-namespace
Role-Manifest Beispiel
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: my-role
namespace: my-namespace
rules:
- apiGroups: [""]
resources:
- pods
verbs:
- create
- get
- list
- watch
- delete
RoleBinding-Manifest Beispiel
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: my-role-binding
namespace: my-namespace
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: my-role
subjects:
- kind: ServiceAccount
name: my-service-account
namespace: my-namespace