From babc372d041a6203bab55208755a5f2c35e999e1 Mon Sep 17 00:00:00 2001 From: Boris Zanetti Date: Sat, 15 Apr 2017 17:53:13 +0200 Subject: [PATCH] move fluentd rbac to yakow --- roles/rbac/tasks/main.yml | 2 -- roles/rbac/templates/fluentd-clusterrole.yml | 9 --------- roles/rbac/templates/fluentd-clusterrolebinding.yml | 13 ------------- 3 files changed, 24 deletions(-) delete mode 100644 roles/rbac/templates/fluentd-clusterrole.yml delete mode 100644 roles/rbac/templates/fluentd-clusterrolebinding.yml diff --git a/roles/rbac/tasks/main.yml b/roles/rbac/tasks/main.yml index 6f7f31575..08b372447 100644 --- a/roles/rbac/tasks/main.yml +++ b/roles/rbac/tasks/main.yml @@ -20,8 +20,6 @@ - {name: 'custom:system:kube-dns', file: 'custom:system:kube-dns-clusterrolebinding.yml', type: clusterrolebinding} - {name: 'custom:system:node', file: 'custom:system:node-clusterrole.yml', type: clusterrole} - {name: 'custom:system:node', file: 'custom:system:node-clusterrolebinding.yml', type: clusterrolebinding} - - {name: fluentd, file: fluentd-clusterrole.yml, type: clusterrole} - - {name: fluentd, file: fluentd-clusterrolebinding.yml, type: clusterrolebinding} - {name: cluster-admin-local, file: cluster-admin-local-clusterrolebinding.yml, type: clusterrolebinding} register: manifests when: inventory_hostname == groups['kube-master'][0] diff --git a/roles/rbac/templates/fluentd-clusterrole.yml b/roles/rbac/templates/fluentd-clusterrole.yml deleted file mode 100644 index 930ae4fa6..000000000 --- a/roles/rbac/templates/fluentd-clusterrole.yml +++ /dev/null @@ -1,9 +0,0 @@ ---- -apiVersion: rbac.authorization.k8s.io/v1beta1 -kind: ClusterRole -metadata: - name: fluentd -rules: - - apiGroups: [""] - resources: ["pods"] - verbs: ["get"] diff --git a/roles/rbac/templates/fluentd-clusterrolebinding.yml b/roles/rbac/templates/fluentd-clusterrolebinding.yml deleted file mode 100644 index 0a66648c3..000000000 --- a/roles/rbac/templates/fluentd-clusterrolebinding.yml +++ /dev/null @@ -1,13 +0,0 @@ ---- -apiVersion: rbac.authorization.k8s.io/v1beta1 -kind: ClusterRoleBinding -metadata: - name: fluentd -roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: fluentd -subjects: -- kind: ServiceAccount - name: fluentd - namespace: kube-system