apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: p-viewer-role
namespace: pepsi
rules:
- apiGroups:
- ""
resourceNames:
- p83
resources:
- pods
verbs:
- list
- get
- watch
Run Code Online (Sandbox Code Playgroud)
当我们在角色中使用 resourceNames 时,以下命令有效
kubectl get pods -n pepsi p83
Run Code Online (Sandbox Code Playgroud)
返回一个适当的值。然而,
kubectl get pods -n pepsi
Run Code Online (Sandbox Code Playgroud)
禁止退货。为什么不列出 p83
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: p-viewer-rolebinding
namespace: pepsi
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: p-viewer-role
subjects:
- apiGroup: rbac.authorization.k8s.io
kind: Group
name: pepsi-project-viewer
namespace: project
Run Code Online (Sandbox Code Playgroud)
归档时间: |
|
查看次数: |
523 次 |
最近记录: |