Make sure cluster roles are applied to the service account the storage provisioner runs under

pull/8909/head
Priya Wadhwa 2020-08-03 15:23:45 -04:00
parent 52bee6dced
commit 5e899a81cc
2 changed files with 6 additions and 4 deletions

View File

@ -40,7 +40,7 @@ subjects:
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: system::leader-locking-storage-provisioner
name: system:persistent-volume-provisioner
namespace: kube-system
labels:
addonmanager.kubernetes.io/mode: EnsureExists
@ -51,6 +51,7 @@ rules:
- endpoints
verbs:
- watch
- create
- apiGroups:
- ""
resourceNames:
@ -60,18 +61,19 @@ rules:
verbs:
- get
- update
- create
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: leader-locking-storage-provisioner
name: system:persistent-volume-provisioner
namespace: kube-system
labels:
addonmanager.kubernetes.io/mode: EnsureExists
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: system::leader-locking-storage-provisioner
name: system:persistent-volume-provisioner
subjects:
- kind: ServiceAccount
name: storage-provisioner

View File

@ -7,4 +7,4 @@ spec:
- ReadWriteOnce
resources:
requests:
storage: 2Gi
storage: 500Mi