Skip to content

Commit

Permalink
Removing ambassador rbac, letting ambassador chart deal with it
Browse files Browse the repository at this point in the history
  • Loading branch information
naseemkullah committed Feb 12, 2019
1 parent e696eac commit 39117b6
Show file tree
Hide file tree
Showing 2 changed files with 7 additions and 72 deletions.
76 changes: 4 additions & 72 deletions helm-charts/seldon-core/templates/rbac.yaml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
{{- if .Values.rbac.enabled }}
{{- if .Values.rbac.service_account.create }}
{{- if .Values.rbac.service_account.create }}
---
apiVersion: v1
kind: ServiceAccount
Expand All @@ -14,7 +14,7 @@ apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: seldon-local
namespace: {{ .Release.Namespace }}
namespace: {{ .Release.Namespace }}
rules:
- apiGroups: ["*"]
resources:
Expand Down Expand Up @@ -46,7 +46,7 @@ apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: seldon-wide
namespace: {{ .Release.Namespace }}
namespace: {{ .Release.Namespace }}
rules:
- apiGroups: ["*"]
resources:
Expand Down Expand Up @@ -78,7 +78,7 @@ apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: seldon-crd-{{ .Release.Namespace }}
namespace: {{ .Release.Namespace }}
namespace: {{ .Release.Namespace }}
rules:
- apiGroups:
- apiextensions.k8s.io
Expand All @@ -99,74 +99,6 @@ subjects:
- kind: ServiceAccount
name: {{ .Values.rbac.service_account.name }}
namespace: {{ .Release.Namespace }}
{{- end }}
{{- if .Values.ambassador.enabled }}
{{- if .Values.single_namespace }}
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: ambassador
rules:
- apiGroups: [""]
resources:
- services
verbs: ["get", "list", "watch"]
- apiGroups: [""]
resources:
- configmaps
verbs: ["create", "update", "patch", "get", "list", "watch"]
- apiGroups: [""]
resources:
- secrets
verbs: ["get", "list", "watch"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: ambassador
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: ambassador
subjects:
- kind: ServiceAccount
name: {{ .Values.rbac.service_account.name }}
namespace: {{ .Release.Namespace }}
{{- end }}
{{- if not .Values.single_namespace }}
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: ambassador
rules:
- apiGroups: [""]
resources:
- services
verbs: ["get", "list", "watch"]
- apiGroups: [""]
resources:
- configmaps
verbs: ["create", "update", "patch", "get", "list", "watch"]
- apiGroups: [""]
resources:
- secrets
verbs: ["get", "list", "watch"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: ambassador
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: ambassador
subjects:
- kind: ServiceAccount
name: {{ .Values.rbac.service_account.name }}
namespace: {{ .Release.Namespace }}
{{- end }}
{{- end }}
{{- end }}
{{- end }}
3 changes: 3 additions & 0 deletions helm-charts/seldon-core/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,9 @@ ambassador:
https:
targetPort: 8443
type: LoadBalancer
rbac:
create: true
namespaced: true
apife:
annotations: null
enabled: true
Expand Down

0 comments on commit 39117b6

Please sign in to comment.