1
0
forked from k-space/kube

Initial commit

This commit is contained in:
2022-08-16 12:40:54 +03:00
commit 7c5cad55e1
122 changed files with 51731 additions and 0 deletions

90
cluster-role-bindings.yml Normal file
View File

@@ -0,0 +1,90 @@
---
# AD/Samba group "Kubernetes Admins" members have full access
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: kubernetes-admins
subjects:
- kind: Group
name: "Kubernetes Admins"
apiGroup: rbac.authorization.k8s.io
roleRef:
kind: ClusterRole
name: cluster-admin
apiGroup: rbac.authorization.k8s.io
---
# AD/Samba group "Developers" members have view access for everything
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: kubernetes-developers
subjects:
- kind: Group
name: Developers
apiGroup: rbac.authorization.k8s.io
roleRef:
kind: ClusterRole
name: view
apiGroup: rbac.authorization.k8s.io
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: developers
namespace: camtiler
subjects:
- kind: Group
name: Developers
apiGroup: rbac.authorization.k8s.io
roleRef:
kind: ClusterRole
name: developers
apiGroup: rbac.authorization.k8s.io
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: developers
namespace: members-site
subjects:
- kind: Group
name: Developers
apiGroup: rbac.authorization.k8s.io
roleRef:
kind: ClusterRole
name: developers
apiGroup: rbac.authorization.k8s.io
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: developers
rules:
- verbs:
- create
- delete
- patch
- update
apiGroups:
- ''
resources:
- configmaps
- pods/attach
- pods/exec
- pods/portforward
- pods/proxy
- verbs:
- patch
apiGroups:
- apps
resources:
- deployments
- statefulsets
- deployments/scale
- statefulsets/scale
- verbs:
- delete
apiGroups:
- ''
resources:
- pods