cloudfoundry-incubator/eirini

View on GitHub
scripts/assets/test-pod-rbac.yml

Summary

Maintainability
Test Coverage
---
apiVersion: v1
kind: ServiceAccount
metadata:
  name: test-pod

---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  name: test-pod
rules:
- apiGroups:
  - ""
  resources:
  - namespaces
  - secrets
  verbs:
  - create
  - delete
  - get
  - list
  - update
- apiGroups:
  - ""
  resources:
  - nodes
  - nodes/proxy
  - nodes/stats
  - nodes/summary
  verbs:
  - get
  - list
- apiGroups:
  - ""
  resources:
  - pods
  - pods/log
  - events
  verbs:
  - create
  - list
  - get
  - watch
  - delete
  - update
- apiGroups:
  - ""
  resources:
  - serviceaccounts
  verbs:
  - create
  - delete
  - get
  - update
- apiGroups:
  - apps
  resources:
  - statefulsets
  verbs:
  - create
  - delete
  - update
  - get
  - list
  - deletecollection
  - watch
- apiGroups:
  - batch
  resources:
  - jobs
  verbs:
  - create
  - delete
  - list
- apiGroups:
  - policy
  resources:
  - podsecuritypolicies
  - poddisruptionbudgets
  verbs:
  - create
  - get
  - delete
  - list
  - use
- apiGroups:
  - rbac.authorization.k8s.io
  resources:
  - roles
  - rolebindings
  verbs:
  - create
  - delete
- apiGroups:
  - admissionregistration.k8s.io
  resources:
  - mutatingwebhookconfigurations
  verbs:
  - create
  - delete


---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: test-pod
roleRef:
  kind: ClusterRole
  name: test-pod
  apiGroup: rbac.authorization.k8s.io
subjects:
- kind: ServiceAccount
  name: test-pod
  namespace: default