Code Review
/
ric-plt
/
ric-dep.git
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
review
|
tree
raw
|
inline
| side by side
Issue-ID: RICAPP-169 - Inclusion of InfluxDB helm chart for KPIMON, AD, TS, QP xApps
[ric-plt/ric-dep.git]
/
helm
/
appmgr
/
templates
/
serviceaccount.yaml
diff --git
a/helm/appmgr/templates/serviceaccount.yaml
b/helm/appmgr/templates/serviceaccount.yaml
index
c873e30
..
13d1c39
100644
(file)
--- a/
helm/appmgr/templates/serviceaccount.yaml
+++ b/
helm/appmgr/templates/serviceaccount.yaml
@@
-26,10
+26,9
@@
metadata:
namespace: {{ include "common.namespace.platform" . }}
---
apiVersion: rbac.authorization.k8s.io/v1beta1
namespace: {{ include "common.namespace.platform" . }}
---
apiVersion: rbac.authorization.k8s.io/v1beta1
-kind: Role
+kind:
Cluster
Role
metadata:
name: {{ include "common.serviceaccountname.appmgr" . }}-{{ include "common.tillerNameSpace" $ctx }}-access
metadata:
name: {{ include "common.serviceaccountname.appmgr" . }}-{{ include "common.tillerNameSpace" $ctx }}-access
- namespace: {{ include "common.tillerDeployNameSpace" $ctx }}
rules:
- apiGroups: [""]
resources: ["pods/portforward"]
rules:
- apiGroups: [""]
resources: ["pods/portforward"]
@@
-40,18
+39,18
@@
rules:
{{- if or (eq (include "common.tillerTLSVerify" $ctx) "true" ) (eq (include "common.tillerTLSAuthenticate" $ctx) "true") }}
- apiGroups: [""]
resources: ["secrets"]
{{- if or (eq (include "common.tillerTLSVerify" $ctx) "true" ) (eq (include "common.tillerTLSAuthenticate" $ctx) "true") }}
- apiGroups: [""]
resources: ["secrets"]
- resourceNames: [ {{ include "common.tillerHelmClientTLSSecret" $ctx | quote }} ]
- verbs: ["get"]
+
#
resourceNames: [ {{ include "common.tillerHelmClientTLSSecret" $ctx | quote }} ]
+ verbs: ["get"
,"list"
]
{{- end }}
---
apiVersion: rbac.authorization.k8s.io/v1beta1
{{- end }}
---
apiVersion: rbac.authorization.k8s.io/v1beta1
-kind: RoleBinding
+kind:
Cluster
RoleBinding
metadata:
name: {{ include "common.serviceaccountname.appmgr" . }}-{{ include "common.tillerNameSpace" $ctx }}-access
metadata:
name: {{ include "common.serviceaccountname.appmgr" . }}-{{ include "common.tillerNameSpace" $ctx }}-access
- namespace: {{ include "common.
tillerDeployNameSpace" $ctx
}}
+ namespace: {{ include "common.
namespace.platform" .
}}
roleRef:
apiGroup: rbac.authorization.k8s.io
roleRef:
apiGroup: rbac.authorization.k8s.io
- kind: Role
+ kind:
Cluster
Role
name: {{ include "common.serviceaccountname.appmgr" . }}-{{ include "common.tillerNameSpace" $ctx }}-access
subjects:
- kind: ServiceAccount
name: {{ include "common.serviceaccountname.appmgr" . }}-{{ include "common.tillerNameSpace" $ctx }}-access
subjects:
- kind: ServiceAccount
@@
-59,25
+58,27
@@
subjects:
namespace: {{ include "common.namespace.platform" . }}
---
apiVersion: rbac.authorization.k8s.io/v1beta1
namespace: {{ include "common.namespace.platform" . }}
---
apiVersion: rbac.authorization.k8s.io/v1beta1
-kind: Role
+kind:
Cluster
Role
metadata:
name: {{ include "common.serviceaccountname.appmgr" . }}-{{ include "common.tillerNameSpace" $ctx }}-getappconfig
metadata:
name: {{ include "common.serviceaccountname.appmgr" . }}-{{ include "common.tillerNameSpace" $ctx }}-getappconfig
- namespace: {{ include "common.tillerNameSpace" $ctx }}
+ #namespace: {{ include "common.tillerNameSpace" $ctx }}
+ #namespace: {{ include "common.namespace.platform" . }}
rules:
- apiGroups: [""]
rules:
- apiGroups: [""]
- resources: ["configmaps", "endpoints"]
+ resources: ["configmaps", "endpoints"
, "services"
]
verbs: ["get", "list", "create", "update", "delete"]
---
apiVersion: rbac.authorization.k8s.io/v1beta1
verbs: ["get", "list", "create", "update", "delete"]
---
apiVersion: rbac.authorization.k8s.io/v1beta1
-kind: RoleBinding
+kind:
Cluster
RoleBinding
metadata:
name: {{ include "common.serviceaccountname.appmgr" . }}-{{ include "common.namespace.xapp" . }}-getappconfig
namespace: {{ include "common.tillerNameSpace" $ctx }}
metadata:
name: {{ include "common.serviceaccountname.appmgr" . }}-{{ include "common.namespace.xapp" . }}-getappconfig
namespace: {{ include "common.tillerNameSpace" $ctx }}
+ #namespace: {{ include "common.namespace.platform" . }}
roleRef:
apiGroup: rbac.authorization.k8s.io
roleRef:
apiGroup: rbac.authorization.k8s.io
- kind: Role
+ kind:
Cluster
Role
name: {{ include "common.serviceaccountname.appmgr" . }}-{{ include "common.tillerNameSpace" $ctx }}-getappconfig
subjects:
- kind: ServiceAccount
name: {{ include "common.serviceaccountname.appmgr" . }}
name: {{ include "common.serviceaccountname.appmgr" . }}-{{ include "common.tillerNameSpace" $ctx }}-getappconfig
subjects:
- kind: ServiceAccount
name: {{ include "common.serviceaccountname.appmgr" . }}
- namespace: {{ include "common.namespace.platform" . }}
\ No newline at end of file
+ namespace: {{ include "common.namespace.platform" . }}