Skip to content

Commit 903a1b4

Browse files
committed
update iam helm
1 parent bfdf61f commit 903a1b4

File tree

3 files changed

+2
-91
lines changed

3 files changed

+2
-91
lines changed

installer/helm/iam/templates/batch-job.yaml renamed to installer/helm/iam/templates/apiserver/batch-job.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ spec:
99
backoffLimit: 3
1010
template:
1111
spec:
12-
serviceAccountName: {{ include "iam.fullname" . }}
12+
serviceAccountName: {{ include "iam.apiServerFullname" . }}
1313
priorityClassName: system-cluster-critical
1414
{{- with .Values.global.imagePullSecrets }}
1515
imagePullSecrets:
@@ -20,6 +20,6 @@ spec:
2020
- name: main
2121
image: "{{ .Values.apiServer.image.repository }}:{{ .Values.apiServer.image.tag | default .Chart.AppVersion }}"
2222
imagePullPolicy: {{ .Values.apiServer.image.pullPolicy }}
23-
command: [ "/gen-k8s-secret.sh", "--service", "{{ include "iam.fullname" . }}", "--namespace",
23+
command: [ "/gen-k8s-secret.sh", "--service", "{{ include "iam.apiServerFullname" . }}", "--namespace",
2424
"{{ .Release.Namespace }}", "--secret", "{{ include "iam.fullname" . }}" ]
2525
{{- end }}

installer/helm/iam/templates/authzserver/rbac.yaml

Lines changed: 0 additions & 42 deletions
Original file line numberDiff line numberDiff line change
@@ -3,45 +3,3 @@ kind: ServiceAccount
33
metadata:
44
name: {{ include "iam.authzServerFullname" . }}
55
namespace: {{ .Release.Namespace }}
6-
---
7-
kind: ClusterRole
8-
apiVersion: rbac.authorization.k8s.io/v1
9-
metadata:
10-
name: {{ include "iam.authzServerFullname" . }}
11-
rules:
12-
- apiGroups: [ "" ]
13-
resources: [ "configmaps" ]
14-
verbs: [ "get", "list", "watch" ]
15-
# Rules below is used generate admission service secret
16-
- apiGroups: [ "certificates.k8s.io" ]
17-
resources: [ "certificatesigningrequests" ]
18-
verbs: [ "get", "list", "create", "delete" ]
19-
- apiGroups: [ "certificates.k8s.io" ]
20-
resources: [ "certificatesigningrequests/approval" ]
21-
verbs: [ "create", "update" ]
22-
- apiGroups: [ "" ]
23-
resources: [ "secrets" ]
24-
verbs: [ "create", "get", "patch" ]
25-
- apiGroups: [ "scheduling.incubator.k8s.io", "scheduling.volcano.sh" ]
26-
resources: [ "queues" ]
27-
verbs: [ "get", "list" ]
28-
- apiGroups: [ "" ]
29-
resources: [ "services" ]
30-
verbs: [ "get" ]
31-
- apiGroups: [ "scheduling.incubator.k8s.io", "scheduling.volcano.sh" ]
32-
resources: [ "podgroups" ]
33-
verbs: [ "get", "list", "watch" ]
34-
35-
---
36-
kind: ClusterRoleBinding
37-
apiVersion: rbac.authorization.k8s.io/v1
38-
metadata:
39-
name: {{ include "iam.authzServerFullname" . }}-role
40-
subjects:
41-
- kind: ServiceAccount
42-
name: {{ include "iam.authzServerFullname" . }}
43-
namespace: {{ .Release.Namespace }}
44-
roleRef:
45-
kind: ClusterRole
46-
name: {{ include "iam.authzServerFullname" . }}
47-
apiGroup: rbac.authorization.k8s.io

installer/helm/iam/templates/rbac.yaml

Lines changed: 0 additions & 47 deletions
This file was deleted.

0 commit comments

Comments
 (0)