Move bind verb resourceNames hint inline of example
This commit is contained in:
@@ -891,6 +891,7 @@ rules:
|
|||||||
- apiGroups: ["rbac.authorization.k8s.io"]
|
- apiGroups: ["rbac.authorization.k8s.io"]
|
||||||
resources: ["clusterroles"]
|
resources: ["clusterroles"]
|
||||||
verbs: ["bind"]
|
verbs: ["bind"]
|
||||||
|
# omit resourceNames to allow binding any ClusterRole
|
||||||
resourceNames: ["admin","edit","view"]
|
resourceNames: ["admin","edit","view"]
|
||||||
---
|
---
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
@@ -908,8 +909,6 @@ subjects:
|
|||||||
name: user-1
|
name: user-1
|
||||||
```
|
```
|
||||||
|
|
||||||
Note that - as with any RBAC verb - you may omit `resourceNames` to allow `user-1` to grant other users _any_ ClusterRole in the namespace `user-1-namespace`.
|
|
||||||
|
|
||||||
When bootstrapping the first roles and role bindings, it is necessary for the initial user to grant permissions they do not yet have.
|
When bootstrapping the first roles and role bindings, it is necessary for the initial user to grant permissions they do not yet have.
|
||||||
To bootstrap initial roles and role bindings:
|
To bootstrap initial roles and role bindings:
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user