Make sure cluster roles are applied to the service account the storage provisioner runs under
parent
52bee6dced
commit
5e899a81cc
|
|
@ -40,7 +40,7 @@ subjects:
|
|||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
name: system::leader-locking-storage-provisioner
|
||||
name: system:persistent-volume-provisioner
|
||||
namespace: kube-system
|
||||
labels:
|
||||
addonmanager.kubernetes.io/mode: EnsureExists
|
||||
|
|
@ -51,6 +51,7 @@ rules:
|
|||
- endpoints
|
||||
verbs:
|
||||
- watch
|
||||
- create
|
||||
- apiGroups:
|
||||
- ""
|
||||
resourceNames:
|
||||
|
|
@ -60,18 +61,19 @@ rules:
|
|||
verbs:
|
||||
- get
|
||||
- update
|
||||
- create
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: leader-locking-storage-provisioner
|
||||
name: system:persistent-volume-provisioner
|
||||
namespace: kube-system
|
||||
labels:
|
||||
addonmanager.kubernetes.io/mode: EnsureExists
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: system::leader-locking-storage-provisioner
|
||||
name: system:persistent-volume-provisioner
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: storage-provisioner
|
||||
|
|
|
|||
|
|
@ -7,4 +7,4 @@ spec:
|
|||
- ReadWriteOnce
|
||||
resources:
|
||||
requests:
|
||||
storage: 2Gi
|
||||
storage: 500Mi
|
||||
Loading…
Reference in New Issue