diff --git a/roles/rbac/tasks/main.yml b/roles/rbac/tasks/main.yml index 6f7f31575..08b372447 100644 --- a/roles/rbac/tasks/main.yml +++ b/roles/rbac/tasks/main.yml @@ -20,8 +20,6 @@ - {name: 'custom:system:kube-dns', file: 'custom:system:kube-dns-clusterrolebinding.yml', type: clusterrolebinding} - {name: 'custom:system:node', file: 'custom:system:node-clusterrole.yml', type: clusterrole} - {name: 'custom:system:node', file: 'custom:system:node-clusterrolebinding.yml', type: clusterrolebinding} - - {name: fluentd, file: fluentd-clusterrole.yml, type: clusterrole} - - {name: fluentd, file: fluentd-clusterrolebinding.yml, type: clusterrolebinding} - {name: cluster-admin-local, file: cluster-admin-local-clusterrolebinding.yml, type: clusterrolebinding} register: manifests when: inventory_hostname == groups['kube-master'][0] diff --git a/roles/rbac/templates/fluentd-clusterrole.yml b/roles/rbac/templates/fluentd-clusterrole.yml deleted file mode 100644 index 930ae4fa6..000000000 --- a/roles/rbac/templates/fluentd-clusterrole.yml +++ /dev/null @@ -1,9 +0,0 @@ ---- -apiVersion: rbac.authorization.k8s.io/v1beta1 -kind: ClusterRole -metadata: - name: fluentd -rules: - - apiGroups: [""] - resources: ["pods"] - verbs: ["get"] diff --git a/roles/rbac/templates/fluentd-clusterrolebinding.yml b/roles/rbac/templates/fluentd-clusterrolebinding.yml deleted file mode 100644 index 0a66648c3..000000000 --- a/roles/rbac/templates/fluentd-clusterrolebinding.yml +++ /dev/null @@ -1,13 +0,0 @@ ---- -apiVersion: rbac.authorization.k8s.io/v1beta1 -kind: ClusterRoleBinding -metadata: - name: fluentd -roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: fluentd -subjects: -- kind: ServiceAccount - name: fluentd - namespace: kube-system