Merge pull request #1888 from CaoShuFeng/roleRef
[authorization] update doc about roleRefreviewable/pr1873/r1^2
commit
d427b0e2e4
|
@ -299,9 +299,8 @@ subjects:
|
||||||
name: jane
|
name: jane
|
||||||
roleRef:
|
roleRef:
|
||||||
kind: Role
|
kind: Role
|
||||||
namespace: default
|
|
||||||
name: pod-reader
|
name: pod-reader
|
||||||
apiVersion: rbac.authorization.k8s.io/v1alpha1
|
apiGroup: rbac.authorization.k8s.io
|
||||||
```
|
```
|
||||||
|
|
||||||
`RoleBindings` may also refer to a `ClusterRole`. However, a `RoleBinding` that
|
`RoleBindings` may also refer to a `ClusterRole`. However, a `RoleBinding` that
|
||||||
|
@ -326,7 +325,7 @@ subjects:
|
||||||
roleRef:
|
roleRef:
|
||||||
kind: ClusterRole
|
kind: ClusterRole
|
||||||
name: secret-reader
|
name: secret-reader
|
||||||
apiVersion: rbac.authorization.k8s.io/v1alpha1
|
apiGroup: rbac.authorization.k8s.io
|
||||||
```
|
```
|
||||||
|
|
||||||
Finally a `ClusterRoleBinding` may be used to grant permissions in all
|
Finally a `ClusterRoleBinding` may be used to grant permissions in all
|
||||||
|
@ -338,14 +337,14 @@ namespaces. The following `ClusterRoleBinding` allows any user in the group
|
||||||
kind: ClusterRoleBinding
|
kind: ClusterRoleBinding
|
||||||
apiVersion: rbac.authorization.k8s.io/v1alpha1
|
apiVersion: rbac.authorization.k8s.io/v1alpha1
|
||||||
metadata:
|
metadata:
|
||||||
name: read-secrets
|
name: read-secrets-global
|
||||||
subjects:
|
subjects:
|
||||||
- kind: Group # May be "User", "Group" or "ServiceAccount"
|
- kind: Group # May be "User", "Group" or "ServiceAccount"
|
||||||
name: manager
|
name: manager
|
||||||
roleRef:
|
roleRef:
|
||||||
kind: ClusterRole
|
kind: ClusterRole
|
||||||
name: secret-reader
|
name: secret-reader
|
||||||
apiVersion: rbac.authorization.k8s.io/v1alpha1
|
apiGroup: rbac.authorization.k8s.io
|
||||||
```
|
```
|
||||||
|
|
||||||
### Referring to Resources
|
### Referring to Resources
|
||||||
|
|
Loading…
Reference in New Issue