授权
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
namespace: user-a
name: pod-reader
rules:
- apiGroups: [""] # /api/v1
resources: ["pods"]
verbs: ["get", "list"]Last updated
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
namespace: user-a
name: pod-reader
rules:
- apiGroups: [""] # /api/v1
resources: ["pods"]
verbs: ["get", "list"]Last updated
GET /api/v1/namespaces/user-a/pods/<pod>
GET /api/v1/namespaces/user-a/podsapiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: pod-reader
namespace: user-a
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: pod-reader
subjects:
- apiGroup: rbac.authorization.k8s.io
kind: User
name: user-a