Improve RBAC doc (#3951)
* Remove spurious cluster-status role description * Indicate controller-manager must be granted controller roles when not run with --use-service-account-credentials
This commit is contained in:
committed by
Andrew Chen
parent
a6f31d4896
commit
2841f6dabe
@@ -416,11 +416,6 @@ When used in a <b>ClusterRoleBinding</b>, it gives full control over every resou
|
|||||||
When used in a <b>RoleBinding</b>, it gives full control over every resource in the rolebinding's namespace, including the namespace itself.</td>
|
When used in a <b>RoleBinding</b>, it gives full control over every resource in the rolebinding's namespace, including the namespace itself.</td>
|
||||||
</tr>
|
</tr>
|
||||||
<tr>
|
<tr>
|
||||||
<td><b>cluster-status</b></td>
|
|
||||||
<td>None</td>
|
|
||||||
<td>Allows read-only access to basic cluster status information.</td>
|
|
||||||
</tr>
|
|
||||||
<tr>
|
|
||||||
<td><b>admin</b></td>
|
<td><b>admin</b></td>
|
||||||
<td>None</td>
|
<td>None</td>
|
||||||
<td>Allows admin access, intended to be granted within a namespace using a <b>RoleBinding</b>.
|
<td>Allows admin access, intended to be granted within a namespace using a <b>RoleBinding</b>.
|
||||||
@@ -531,6 +526,8 @@ This is commonly used by add-on API servers for unified authentication and autho
|
|||||||
The [Kubernetes controller manager](/docs/admin/kube-controller-manager/) runs core control loops.
|
The [Kubernetes controller manager](/docs/admin/kube-controller-manager/) runs core control loops.
|
||||||
When invoked with `--use-service-account-credentials`, each control loop is started using a separate service account.
|
When invoked with `--use-service-account-credentials`, each control loop is started using a separate service account.
|
||||||
Corresponding roles exist for each control loop, prefixed with `system:controller:`.
|
Corresponding roles exist for each control loop, prefixed with `system:controller:`.
|
||||||
|
If the controller manager is not started with `--use-service-account-credentials`,
|
||||||
|
it runs all control loops using its own credential, which must be granted all the relevant roles.
|
||||||
These roles include:
|
These roles include:
|
||||||
|
|
||||||
* system:controller:attachdetach-controller
|
* system:controller:attachdetach-controller
|
||||||
|
|||||||
Reference in New Issue
Block a user