Skip to content

Commit

Permalink
refactor ovn clusterrole (#3755)
Browse files Browse the repository at this point in the history
Signed-off-by: 马洪贞 <hzma@alauda.io>
  • Loading branch information
hongzhen-ma committed Feb 26, 2024
1 parent 76ea1c1 commit b5f7a63
Show file tree
Hide file tree
Showing 3 changed files with 153 additions and 78 deletions.
77 changes: 51 additions & 26 deletions charts/kube-ovn/templates/ovn-CR.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -54,17 +54,28 @@ rules:
- ""
resources:
- pods
- pods/exec
- namespaces
- nodes
- configmaps
verbs:
- create
- get
- list
- patch
- watch
- apiGroups:
- ""
resources:
- nodes
verbs:
- get
- list
- patch
- update
- watch
- apiGroups:
- ""
resources:
- pods/exec
verbs:
- create
- apiGroups:
- "k8s.cni.cncf.io"
resources:
Expand All @@ -74,40 +85,53 @@ rules:
- apiGroups:
- ""
- networking.k8s.io
- apps
resources:
- networkpolicies
- daemonsets
- configmaps
verbs:
- get
- list
- watch
- apiGroups:
- ""
- apps
resources:
- daemonsets
verbs:
- get
- apiGroups:
- ""
resources:
- services
- services/status
verbs:
- get
- list
- update
- create
- delete
- watch
- apiGroups:
- ""
- networking.k8s.io
- apps
- extensions
resources:
- services
- endpoints
verbs:
- create
- update
- get
- list
- watch
- apiGroups:
- apps
resources:
- statefulsets
- deployments
- deployments/scale
verbs:
- get
- list
- create
- delete
- update
- patch
- get
- list
- watch
- apiGroups:
- ""
resources:
Expand Down Expand Up @@ -148,8 +172,6 @@ rules:
- patch
- apiGroups:
- ""
- networking.k8s.io
- apps
resources:
- services
- endpoints
Expand All @@ -173,29 +195,34 @@ metadata:
rules:
- apiGroups:
- "kubeovn.io"
- ""
resources:
- subnets
- provider-networks
- ovn-eips
- ovn-eips/status
- ips
- pods
verbs:
- get
- list
- patch
- update
- watch
- apiGroups:
- ""
- "kubeovn.io"
resources:
- pods
- ovn-eips
- ovn-eips/status
- nodes
- configmaps
verbs:
- get
- list
- patch
- watch
- apiGroups:
- "kubeovn.io"
resources:
- ips
verbs:
- get
- update
- apiGroups:
- ""
resources:
Expand All @@ -222,8 +249,6 @@ rules:
- get
- list
- apiGroups:
- ""
- networking.k8s.io
- apps
resources:
- daemonsets
Expand Down
77 changes: 51 additions & 26 deletions dist/images/install.sh
Original file line number Diff line number Diff line change
Expand Up @@ -2831,8 +2831,6 @@ rules:
- patch
- apiGroups:
- ""
- networking.k8s.io
- apps
resources:
- services
- endpoints
Expand Down Expand Up @@ -2923,17 +2921,28 @@ rules:
- ""
resources:
- pods
- pods/exec
- namespaces
- nodes
- configmaps
verbs:
- create
- get
- list
- patch
- watch
- apiGroups:
- ""
resources:
- nodes
verbs:
- get
- list
- patch
- update
- watch
- apiGroups:
- ""
resources:
- pods/exec
verbs:
- create
- apiGroups:
- "k8s.cni.cncf.io"
resources:
Expand All @@ -2943,40 +2952,53 @@ rules:
- apiGroups:
- ""
- networking.k8s.io
- apps
resources:
- networkpolicies
- daemonsets
- configmaps
verbs:
- get
- list
- watch
- apiGroups:
- ""
- apps
resources:
- daemonsets
verbs:
- get
- apiGroups:
- ""
resources:
- services
- services/status
verbs:
- get
- list
- update
- create
- delete
- watch
- apiGroups:
- ""
- networking.k8s.io
- apps
- extensions
resources:
- services
- endpoints
verbs:
- create
- update
- get
- list
- watch
- apiGroups:
- apps
resources:
- statefulsets
- deployments
- deployments/scale
verbs:
- get
- list
- create
- delete
- update
- patch
- get
- list
- watch
- apiGroups:
- ""
resources:
Expand Down Expand Up @@ -3031,29 +3053,34 @@ metadata:
rules:
- apiGroups:
- "kubeovn.io"
- ""
resources:
- subnets
- provider-networks
- ovn-eips
- ovn-eips/status
- ips
- pods
verbs:
- get
- list
- patch
- update
- watch
- apiGroups:
- ""
- "kubeovn.io"
resources:
- pods
- ovn-eips
- ovn-eips/status
- nodes
- configmaps
verbs:
- get
- list
- patch
- watch
- apiGroups:
- "kubeovn.io"
resources:
- ips
verbs:
- get
- update
- apiGroups:
- ""
resources:
Expand Down Expand Up @@ -3101,8 +3128,6 @@ rules:
- get
- list
- apiGroups:
- ""
- networking.k8s.io
- apps
resources:
- daemonsets
Expand Down

0 comments on commit b5f7a63

Please sign in to comment.