Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

beta to stable #2895

Closed
wants to merge 92 commits into from
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
92 commits
Select commit Hold shift + click to select a range
8898ac7
feat: enable rotation of service account tokens
linki Jan 7, 2020
c0976b7
chore: disable non-expiring service account tokens
linki Jan 7, 2020
9fa1251
fix: allow non-root apps to read service account token
linki Jan 8, 2020
929878e
feat: make service account token rotation configurable
linki Jan 8, 2020
0940b38
ref: change config so it doesn't roll workers when disabled
linki Jan 14, 2020
66192d6
Revert "Revert "RBAC: rollout [2/2]""
mikkeloscar Jan 14, 2020
bfb99bf
Whitelist credentials-provider as a system-user
mikkeloscar Jan 14, 2020
82d3470
Merge pull request #2862 from zalando-incubator/revert-2861-revert-24…
linki Jan 14, 2020
9c7a9cc
remove zmon components
Jan 14, 2020
0af95e6
Revert "Revert "Revert "RBAC: rollout [2/2]"""
mikkeloscar Jan 14, 2020
b52add0
Merge pull request #2864 from zalando-incubator/revert-2862-revert-28…
mikkeloscar Jan 14, 2020
65ddabe
Merge pull request #2863 from pitr/cleanup-zmon
mikkeloscar Jan 14, 2020
19b7437
Revert "Revert "Revert "Revert "RBAC: rollout [2/2]""""
mikkeloscar Jan 14, 2020
2f017d3
Give api-monitoring-controller access to configmap in kube-system
mikkeloscar Jan 15, 2020
70d7294
Merge pull request #2865 from zalando-incubator/revert-2864-revert-28…
mikkeloscar Jan 15, 2020
2cb9561
Merge dev to dev-to-alpha
zalando-teapot-robot Jan 15, 2020
d6d57ce
chore: update ExternalDNS to v0.5.18
linki Jan 10, 2020
ebeceeb
Give PowerUser/ReadOnly access to persistentvolumes via RBAC
mikkeloscar Jan 15, 2020
daa9169
Merge pull request #2855 from zalando-incubator/external-dns-v0.5.18
Jan 15, 2020
81f6dd1
Merge dev to dev-to-alpha
zalando-teapot-robot Jan 15, 2020
de84967
Merge pull request #2869 from zalando-incubator/poweruser-persistentv…
linki Jan 15, 2020
193024e
Merge dev to dev-to-alpha
zalando-teapot-robot Jan 15, 2020
6f85875
Update admission-controller (crd admitter)
mikkeloscar Jan 15, 2020
3dd3abf
Merge pull request #2870 from zalando-incubator/crd-admit-update
mikkeloscar Jan 15, 2020
c0a07a7
Merge dev to dev-to-alpha
zalando-teapot-robot Jan 15, 2020
cc0222c
Allow access to PriorityClasses (PowerUser/ReadOnly)
aermakov-zalando Jan 17, 2020
0e90aa1
Allow publishing events as well
aermakov-zalando Jan 17, 2020
4a2d806
Merge pull request #2871 from zalando-incubator/poweruser-allow-prior…
aermakov-zalando Jan 17, 2020
65d7985
Merge dev to dev-to-alpha
zalando-teapot-robot Jan 17, 2020
611a752
Move lightstep token to the private repo
aermakov-zalando Jan 17, 2020
66cc1d1
Move etcd_scalyr_key as well
aermakov-zalando Jan 17, 2020
1717c00
Merge pull request #2839 from zalando-incubator/bound-service-account…
szuecs Jan 17, 2020
63dbac5
Merge dev to dev-to-alpha
zalando-teapot-robot Jan 17, 2020
f06dbdc
VPA: update secret _before_ updating the pod
aermakov-zalando Jan 17, 2020
33c8dfb
Merge pull request #2874 from zalando-incubator/fix-vpa-admitter
aermakov-zalando Jan 17, 2020
82b7915
Merge dev to dev-to-alpha
zalando-teapot-robot Jan 17, 2020
2486c89
Update auth webhook to 0.7.4
aermakov-zalando Jan 17, 2020
61ead80
Merge pull request #2873 from zalando-incubator/update-webhook
aermakov-zalando Jan 17, 2020
d0f1504
Merge dev to dev-to-alpha
zalando-teapot-robot Jan 17, 2020
9efa149
Collaborator role: fix apiGroups
aermakov-zalando Jan 20, 2020
aeb3d18
Remove resourceNames from the role
aermakov-zalando Jan 20, 2020
e98f4c8
Merge pull request #2876 from zalando-incubator/fix-visibility-rbac
aermakov-zalando Jan 20, 2020
6694f89
Merge dev to dev-to-alpha
zalando-teapot-robot Jan 20, 2020
3b22201
Merge pull request #2872 from zalando-incubator/move-lightstep-token
linki Jan 20, 2020
5e0c7c3
Merge dev to dev-to-alpha
zalando-teapot-robot Jan 20, 2020
612982f
chore: update kube-state-metrics to v1.9.1
linki Jan 20, 2020
635efd7
Make it possible to allow collaborator admin access in pet clusters
aermakov-zalando Jan 20, 2020
abb387c
Merge pull request #2878 from zalando-incubator/state-metrics
mikkeloscar Jan 20, 2020
438a2c4
Merge dev to dev-to-alpha
zalando-teapot-robot Jan 20, 2020
dca023e
Merge pull request #2877 from zalando-incubator/collaborator-pet-cluster
aermakov-zalando Jan 20, 2020
9a628ca
Merge dev to dev-to-alpha
zalando-teapot-robot Jan 20, 2020
add8133
chore: update kube-state-metrics to v1.9.2
linki Jan 20, 2020
07553a3
Merge pull request #2880 from zalando-incubator/ksm-v1.9.2
linki Jan 20, 2020
f946009
Merge dev to dev-to-alpha
zalando-teapot-robot Jan 20, 2020
7513f5c
Collaborators: bind something that actually exists
aermakov-zalando Jan 20, 2020
dc75cca
Set various configuration for virtual memory
arjunrn Jan 20, 2020
42bb3c7
Merge pull request #2882 from zalando-incubator/fix-collaborator-role
aermakov-zalando Jan 20, 2020
365cebc
Merge dev to dev-to-alpha
zalando-teapot-robot Jan 20, 2020
01a0a25
Merge pull request #2866 from zalando-incubator/dev-to-alpha
aermakov-zalando Jan 21, 2020
50ce8c1
Merge alpha to alpha-to-beta
zalando-teapot-robot Jan 21, 2020
9ef5d39
Update k8s-authnz-webhook
aermakov-zalando Jan 21, 2020
cf6eb66
Add an e2e test for the mirror pods
aermakov-zalando Jan 21, 2020
54d14ee
Merge pull request #2879 from zalando-incubator/set-vm-parameters
arjunrn Jan 21, 2020
1452239
Merge dev to dev-to-alpha
zalando-teapot-robot Jan 21, 2020
77f8f1c
Merge pull request #2885 from zalando-incubator/fix-mirror-pods
aermakov-zalando Jan 21, 2020
0b7270d
Merge dev to dev-to-alpha
zalando-teapot-robot Jan 21, 2020
9f0cd65
kubelet: drop readOnlyPort
aermakov-zalando Jan 21, 2020
b16f7f7
Deployment role: sort the actions
aermakov-zalando Jan 22, 2020
9f20120
Deployment role: add missing privileges
aermakov-zalando Jan 22, 2020
d990b5d
Update to 1.15.9
aermakov-zalando Jan 22, 2020
6b0d387
Remove the runcmd directive because cloud-final does not start before…
arjunrn Jan 22, 2020
bea2b7e
Merge pull request #2887 from zalando-incubator/update-1-15-9
aermakov-zalando Jan 22, 2020
d60af88
Merge dev to dev-to-alpha
zalando-teapot-robot Jan 22, 2020
821ccf6
Merge pull request #2884 from zalando-incubator/remove-readonly-port
mikkeloscar Jan 22, 2020
8ba6aa5
Merge dev to dev-to-alpha
zalando-teapot-robot Jan 22, 2020
8838370
Merge pull request #2888 from zalando-incubator/fix-deployment-resources
mikkeloscar Jan 22, 2020
a713f31
Merge dev to dev-to-alpha
zalando-teapot-robot Jan 22, 2020
117321e
Restore the kubectl node role label
aermakov-zalando Jan 22, 2020
f21e1e2
Merge pull request #2890 from zalando-incubator/fix-node-labels
aermakov-zalando Jan 22, 2020
f1be343
Merge dev to dev-to-alpha
zalando-teapot-robot Jan 22, 2020
0b7b6c8
Merge pull request #2886 from zalando-incubator/dev-to-alpha
gargravarr Jan 23, 2020
8557c4a
Merge alpha to alpha-to-beta
zalando-teapot-robot Jan 23, 2020
2d3538c
CDP controller role: allow the use of v2 tokens
aermakov-zalando Jan 23, 2020
69074df
Merge pull request #2891 from zalando-incubator/cdp-controller-v2
aermakov-zalando Jan 23, 2020
c308026
Merge dev to dev-to-alpha
zalando-teapot-robot Jan 23, 2020
ddee00b
RBAC: allow events.k8s.io for events
aermakov-zalando Jan 23, 2020
a436da9
Merge pull request #2894 from zalando-incubator/events-k8s-io
aermakov-zalando Jan 23, 2020
3bd482e
Merge dev to dev-to-alpha
zalando-teapot-robot Jan 23, 2020
35c5312
Merge pull request #2893 from zalando-incubator/dev-to-alpha
szuecs Jan 23, 2020
ee52a44
Merge alpha to alpha-to-beta
zalando-teapot-robot Jan 23, 2020
3059a7d
Merge pull request #2883 from zalando-incubator/alpha-to-beta
mikkeloscar Jan 24, 2020
7578dfa
Merge beta to beta-to-stable
zalando-teapot-robot Jan 24, 2020
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
46 changes: 39 additions & 7 deletions cluster/cluster.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -568,63 +568,95 @@ Resources:
- Action:
- 'acm:*'
- 'apigateway:*'
- 'application-autoscaling:*'
- 'appsync:*'
- 'athena:*'
- 'automation:*'
- 'autoscaling:*'
- 'autoscaling-plans:*'
- 'application-autoscaling:*'
- 'autoscaling:*'
- 'aws-marketplace:View*'
- 'aws-portal:View*'
- 'aws-portal:ViewAccount'
- 'aws-portal:ViewBilling'
- 'aws-portal:ViewUsage'
- 'backup-storage:*'
- 'backup:*'
- 'budgets:ViewBudget'
- 'ce:*'
- 'cloudformation:*'
- 'cloudfront:*'
- 'cloudsearch:*'
- 'cloudtrail:DescribeTrails'
- 'cloudtrail:GetEventSelectors'
- 'cloudtrail:GetTrailStatus'
- 'cloudtrail:LookupEvents'
- 'cloudtrail:StartLogging'
- 'cloudwatch:*'
- 'config:*'
- 'cur:DescribeReportDefinitions'
- 'datapipeline:*'
- 'dax:*'
- 'devicefarm:*'
- 'dlm:*'
- 'ds:*'
- 'dynamodb:*'
- 'ec2:*'
- 'ec2-reports:*'
- 'ec2:*'
- 'ecr:Get*'
- 'ecr:BatchGetImage'
- 'ecr:BatchCheckLayerAvailability'
- 'ecr:Describe*'
- 'ecr:List*'
- 'elasticache:*'
- 'elasticfilesystem:*'
- 'elasticloadbalancing:*'
- 'elasticmapreduce:*'
- 'elastictranscoder:*'
- 'es:*'
- 'events:*'
- 'firehose:*'
- 'glacier:*'
- 'glue:*'
- 'health:*'
- 'iam:*'
- 'kafka:*'
- 'kinesis:*'
- 'kinesisanalytics:*'
- 'kms:*'
- 'lambda:*'
- 'lex:*'
- 'logs:*'
- 'machinelearning:*'
- 'kafka:*'
- 'mq:*'
- 'pricing:Describe*'
- 'pricing:Get*'
- 'quicksight:*'
- 'rds:*'
- 'redshift:*'
- 'rekognition:*'
- 'resource-groups:*'
- 'route53:*'
- 'route53domains:Get*'
- 'route53domains:List*'
- 's3:*'
- 'sagemaker:*'
- 'sdb:*'
- 'secretsmanager:*'
- 'serviceQuotas:Get*'
- 'serviceQuotas:List*'
- 'ses:*'
- 'sns:*'
- 'sqs:*'
- 'ssm:*'
- 'states:*'
- 'storagegateway:*'
- 'sts:*'
- 'support:*'
- 'swf:*'
- 'tag:get*'
- 'transfer:*'
- 'trustedadvisor:*'
- 'firehose:*'
- 'lambda:*'
- 'waf-regional:*'
- 'waf:*'
Effect: Allow
Resource: '*'
Version: 2012-10-17
Expand Down
74 changes: 21 additions & 53 deletions cluster/config-defaults.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -71,11 +71,7 @@ skipper_ingress_lightstep_min_period: "500ms"
skipper_ingress_lightstep_max_period: "2500ms"
# set to "log-events" to enable
skipper_ingress_lightstep_log_events: ""
{{if eq .Environment "production"}}
lightstep_token: "aws:kms:AQICAHgrx06TPoR1aNmcPHJjFu5mmoICT5KJkx2fsTJpmXmbNAH+8Ml18b8ZkUO/0KAwtIZTAAAAfjB8BgkqhkiG9w0BBwagbzBtAgEAMGgGCSqGSIb3DQEHATAeBglghkgBZQMEAS4wEQQMSf79AuT/RI5rvWWjAgEQgDuN7obV7JD4iBMnOJ4Th93DfM5j572dXjf+gWmHx4JKMTTJPX2w6hgfQXX3LjI49l0p479a6IXIlZJOSg=="
{{else}}
lightstep_token: "aws:kms:AQICAHgrx06TPoR1aNmcPHJjFu5mmoICT5KJkx2fsTJpmXmbNAHvvYXdV1r7NviF5S+Jyx5zAAAAfjB8BgkqhkiG9w0BBwagbzBtAgEAMGgGCSqGSIb3DQEHATAeBglghkgBZQMEAS4wEQQMQBqSQk/2TuQOsHGOAgEQgDsrNbCwF4AxoQXZuxXUOPnuQhFCY02EhWcB4xqmjFy8DelZtiCldRtxRdLyDL4uXiEyV8vOFyhxgqso/A=="
{{end}}
lightstep_token: ""

# tokeninfo
skipper_ingress_tokeninfo_cpu: "1000m"
Expand Down Expand Up @@ -105,50 +101,10 @@ cadvisor_memory: "150Mi"
node_exporter_cpu: "20m"
node_exporter_memory: "75Mi"

# Monitoring settings
{{if eq .Environment "e2e"}}
zmon_agent_replicas: "0"
zmon_aws_agent_replicas: "0"
zmon_redis_replicas: "0"
zmon_scheduler_replicas: "0"
zmon_scheduler_mem: "0Gi"
zmon_worker_replicas: "0"
zmon_worker_mem: "0Gi"
zmon_worker_cpu: "0"
zmon_worker_count: "0"
{{else if eq .Environment "production"}}
zmon_agent_replicas: "1"
zmon_aws_agent_replicas: "1"
zmon_redis_replicas: "1"
zmon_scheduler_replicas: "1"
zmon_scheduler_mem: "2.5Gi"
zmon_worker_replicas: "6"
zmon_worker_mem: "4Gi"
zmon_worker_cpu: "750m"
zmon_worker_count: "16"
{{else}}
zmon_agent_replicas: "1"
zmon_aws_agent_replicas: "1"
zmon_redis_replicas: "1"
zmon_scheduler_replicas: "1"
zmon_scheduler_mem: "2.5Gi"
zmon_worker_replicas: "4"
zmon_worker_mem: "4Gi"
zmon_worker_cpu: "750m"
zmon_worker_count: "16"
{{end}}
zmon_scalyr_region: "eu"
zmon_worker_version: "v209-py2eol-61-gcd2c760-v251-py2eol"
zmon_agent_version: "0.4-19-ga12da10-zv5"
# Logging settings
logging_s3_bucket: "zalando-logging-{{.InfrastructureAccount | getAWSAccountID}}-{{.Region}}"
scalyr_team_token: ""

zmon_redis_mem: "1Gi"
zmon_agent_mem: "500Mi"
zmon_agent_cpu: "200m"
zmon_aws_agent_mem: "200Mi"
zmon_aws_agent_cpu: "100m"

prometheus_cpu: "1000m"
prometheus_mem: "4Gi"
prometheus_mem_min: "1Gi"
Expand Down Expand Up @@ -231,19 +187,13 @@ etcd_instance_count: "5"
etcd_instance_count: "3"
{{end}}

{{if ne .Environment "e2e"}}
etcd_scalyr_key: "aws:kms:AQECAHgNxQ3yghAnRNmN6GyaSh8l0hGHUap3hNqu00tmcgcOxgAAAIwwgYkGCSqGSIb3DQEHBqB8MHoCAQAwdQYJKoZIhvcNAQcBMB4GCWCGSAFlAwQBLjARBAwrD+79PBvwdNnIXGICARCASEVQTLFyRAWL1OWE1WSl19lm5wY6Cj38wWse8esMBlxUvYSDRZqqyKMJieZpDbAxaAnJO6FKEJdpOoyU8GsV8At/43DhtaHkdA=="
{{else}}
etcd_scalyr_key: ""
{{end}}

dynamodb_service_link_enabled: "false"

cluster_dns: "coredns"
coredns_log_svc_names: "true"

kuberuntu_image_v1_14: {{ amiID "zalando-ubuntu-kubernetes-production-v1.14.8-master-77" "861068367966" }}
kuberuntu_image_v1_15: {{ amiID "zalando-ubuntu-kubernetes-production-v1.15.6-master-81" "861068367966" }}
kuberuntu_image_v1_15: {{ amiID "zalando-ubuntu-kubernetes-production-v1.15.9-master-89" "861068367966" }}

# Feature toggle to allow gradual decommissioning of ingress-template-controller
enable_ingress_template_controller: "false"
Expand Down Expand Up @@ -295,6 +245,8 @@ apiserver_proxy: "true"
# when set to true, service account tokens can be used from outside the cluster
# requires apiserver_proxy to be set to "true"
allow_external_service_accounts: "false"
# issue service account tokens with expiration time.
rotate_service_account_tokens: "false"

# use kube-aws-iam-controller for kube-system components
kube_aws_iam_controller_kube_system_enable: "true"
Expand All @@ -308,3 +260,19 @@ custom_dns_zone_nameservers: "" # space seperated list of nameserver IP addresse

# prefix prepended to ownership TXT records for external-dns
external_dns_ownership_prefix: ""

# special roles for test/pet clusters
{{if eq .Cluster.Environment "e2e"}}
collaborator_administrator_access: "true"
{{else}}
collaborator_administrator_access: "false"
{{end}}

# enable legacy serviceaccounts for smooth RBAC migration
enable_operator_sa: "false"
enable_default_sa: "false"
enable_cdp_sa: "false"

# virtual memory configuration
vm_dirty_background_bytes: ""
vm_dirty_bytes: ""
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ spec:
version: v0.6.1-internal.4
component: vpa
annotations:
config/hash: {{"secret.yaml" | manifestHash}}
config/hash: {{"02-secret.yaml" | manifestHash}}
spec:
priorityClassName: system-cluster-critical
serviceAccountName: vpa-admission-controller
Expand Down
2 changes: 1 addition & 1 deletion cluster/manifests/admission-control/daemonset.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ spec:
effect: NoSchedule
containers:
- name: cluster-autoscaler
image: registry.opensource.zalan.do/teapot/admission-controller:master-45
image: registry.opensource.zalan.do/teapot/admission-controller:master-54
command:
- /registry-proxy
- --address=127.0.0.1:8285
Expand Down
2 changes: 2 additions & 0 deletions cluster/manifests/dashboard/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -47,3 +47,5 @@ spec:
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 1000
securityContext:
fsGroup: 1000
9 changes: 9 additions & 0 deletions cluster/manifests/deletions.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -22,3 +22,12 @@ post_apply:
- name: ingress-template-controller
kind: ClusterRoleBinding
{{ end }}
- name: poweruser-new
kind: ClusterRoleBinding
- name: readonly-new
kind: ClusterRoleBinding
- name: zmon-external-new
kind: ClusterRoleBinding
- name: collaborator
namespace: visibility
kind: RoleBinding
8 changes: 5 additions & 3 deletions cluster/manifests/external-dns/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ metadata:
namespace: kube-system
labels:
application: external-dns
version: v0.5.17
version: v0.5.18
spec:
strategy:
type: Recreate
Expand All @@ -16,7 +16,7 @@ spec:
metadata:
labels:
application: external-dns
version: v0.5.17
version: v0.5.18
{{ if eq .ConfigItems.kube_aws_iam_controller_kube_system_enable "false"}}
annotations:
iam.amazonaws.com/role: "{{ .LocalID }}-app-external-dns"
Expand All @@ -30,7 +30,7 @@ spec:
serviceAccountName: external-dns
containers:
- name: external-dns
image: pierone.stups.zalan.do/teapot/external-dns:v0.5.17
image: registry.opensource.zalan.do/teapot/external-dns:v0.5.18
args:
- --source=service
- --source=ingress
Expand Down Expand Up @@ -65,6 +65,8 @@ spec:
runAsUser: 65534
capabilities:
drop: ["ALL"]
securityContext:
fsGroup: 65534
{{ if eq .ConfigItems.kube_aws_iam_controller_kube_system_enable "true"}}
volumes:
- name: aws-iam-credentials
Expand Down
2 changes: 2 additions & 0 deletions cluster/manifests/heapster/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,8 @@ spec:
value: "1"
priorityClassName: system-cluster-critical
serviceAccountName: heapster
securityContext:
fsGroup: 65534
containers:
- image: registry.opensource.zalan.do/teapot/heapster:v1.5.4
name: heapster
Expand Down
1 change: 1 addition & 0 deletions cluster/manifests/kube-proxy/configmap.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,7 @@ data:
enableProfiling: false
featureGates:
TaintBasedEvictions: true
BoundServiceAccountTokenVolume: {{ .Cluster.ConfigItems.rotate_service_account_tokens }}
healthzBindAddress: 0.0.0.0:10256
hostnameOverride: ""
iptables:
Expand Down
8 changes: 5 additions & 3 deletions cluster/manifests/kube-state-metrics/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ metadata:
namespace: kube-system
labels:
application: kube-state-metrics
version: v1.8.0
version: v1.9.2
spec:
replicas: 1
selector:
Expand All @@ -15,7 +15,7 @@ spec:
metadata:
labels:
application: kube-state-metrics
version: v1.8.0
version: v1.9.2
spec:
dnsConfig:
options:
Expand All @@ -25,7 +25,7 @@ spec:
serviceAccountName: kube-state-metrics
containers:
- name: kube-state-metrics
image: registry.opensource.zalan.do/teapot/kube-state-metrics:v1.8.0
image: registry.opensource.zalan.do/teapot/kube-state-metrics:v1.9.2
ports:
- containerPort: 8080
name: http-metrics
Expand All @@ -47,3 +47,5 @@ spec:
runAsUser: 65534
capabilities:
drop: ["ALL"]
securityContext:
fsGroup: 65534
1 change: 1 addition & 0 deletions cluster/manifests/psp/pod_security_policy.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -43,3 +43,4 @@ spec:
- persistentVolumeClaim
- downwardAPI
- configMap
- projected
3 changes: 3 additions & 0 deletions cluster/manifests/roles/cdp-controller-rbac.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -94,3 +94,6 @@ subjects:
- apiGroup: rbac.authorization.k8s.io
kind: User
name: zalando-iam:zalando:service:credprov-cdp-controller-cluster-token
- apiGroup: rbac.authorization.k8s.io
kind: User
name: zalando-iam:zalando:service:stups_cdp-controller
11 changes: 5 additions & 6 deletions cluster/manifests/roles/collaborator-roles.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,11 +5,10 @@ metadata:
namespace: visibility
rules:
- apiGroups:
- ""
- apps
- extensions
resources:
- daemonsets
resourceNames:
- logging-agent
verbs:
- create
- update
Expand All @@ -19,12 +18,12 @@ rules:
kind: RoleBinding
apiVersion: rbac.authorization.k8s.io/v1
metadata:
name: collaborator
name: collaborator-binding
namespace: visibility
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: collaborator-visibility
kind: Role
name: collaborator
subjects:
- kind: Group
name: CollaboratorPowerUser
Expand Down
2 changes: 1 addition & 1 deletion cluster/manifests/roles/poweruser-binding.yaml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
kind: ClusterRoleBinding
apiVersion: rbac.authorization.k8s.io/v1
metadata:
name: poweruser-new # TODO: migrate name
name: poweruser
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
Expand Down
Loading