This repository was archived by the owner on Feb 6, 2025. It is now read-only.
File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -49,30 +49,6 @@ metadata:
4949 name: kucero
5050 namespace: kube-system
5151---
52- apiVersion: policy/v1beta1
53- kind: PodSecurityPolicy
54- metadata:
55- name: kucero
56- spec:
57- allowedHostPaths:
58- - pathPrefix: /etc/kubernetes/pki
59- readOnly: true
60- - pathPrefix: /var/lib/kubelet/pki
61- readOnly: true
62- fsGroup:
63- rule: RunAsAny
64- hostPID: true
65- privileged: true
66- runAsUser:
67- rule: RunAsAny
68- seLinux:
69- rule: RunAsAny
70- supplementalGroups:
71- rule: RunAsAny
72- volumes:
73- - secret
74- - hostPath
75- ---
7652apiVersion: rbac.authorization.k8s.io/v1
7753kind: Role
7854metadata:
@@ -146,14 +122,6 @@ rules:
146122 - pods/eviction
147123 verbs:
148124 - create
149- - apiGroups:
150- - extensions
151- resourceNames:
152- - kucero
153- resources:
154- - podsecuritypolicies
155- verbs:
156- - use
157125- apiGroups:
158126 - certificates.k8s.io
159127 resourceNames:
@@ -225,6 +193,19 @@ subjects:
225193 name: kucero
226194 namespace: kube-system
227195---
196+ apiVersion: rbac.authorization.k8s.io/v1
197+ kind: ClusterRoleBinding
198+ metadata:
199+ name: suse:caasp:psp:kucero
200+ roleRef:
201+ kind: ClusterRole
202+ name: suse:caasp:psp:privileged
203+ apiGroup: rbac.authorization.k8s.io
204+ subjects:
205+ - kind: ServiceAccount
206+ name: kucero
207+ namespace: kube-system
208+ ---
228209apiVersion: apps/v1
229210kind: DaemonSet
230211metadata:
Original file line number Diff line number Diff line change @@ -107,7 +107,7 @@ var (
107107 Dex : & AddonVersion {"2.23.0" , 7 },
108108 Gangway : & AddonVersion {"3.1.0-rev5" , 5 },
109109 MetricsServer : & AddonVersion {"0.3.6" , 0 },
110- Kucero : & AddonVersion {"1.1.1" , 0 },
110+ Kucero : & AddonVersion {"1.1.1" , 1 },
111111 PSP : & AddonVersion {"" , 2 },
112112 },
113113 },
You can’t perform that action at this time.
0 commit comments