890964eca0
- Updated apiserver-anchor with a liveness probe. - Changed apiserver liveness probe to query kubectl. This allows the pod to restart if it looses access to etcd. Change-Id: I0ef9cbc941a0533268e4f499a1333e88be3e43a3
43 lines
1.1 KiB
YAML
43 lines
1.1 KiB
YAML
{{/*
|
|
Copyright 2018 AT&T Intellectual Property. All other rights reserved.
|
|
|
|
Licensed under the Apache License, Version 2.0 (the "License");
|
|
you may not use this file except in compliance with the License.
|
|
You may obtain a copy of the License at
|
|
|
|
http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
Unless required by applicable law or agreed to in writing, software
|
|
distributed under the License is distributed on an "AS IS" BASIS,
|
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
See the License for the specific language governing permissions and
|
|
limitations under the License.
|
|
*/}}
|
|
|
|
---
|
|
kind: ClusterRole
|
|
apiVersion: rbac.authorization.k8s.io/v1
|
|
metadata:
|
|
name: apiserver
|
|
namespace: kube-system
|
|
rules:
|
|
- apiGroups: [""]
|
|
resources:
|
|
- nodes
|
|
verbs:
|
|
- get
|
|
---
|
|
kind: ClusterRoleBinding
|
|
apiVersion: rbac.authorization.k8s.io/v1
|
|
metadata:
|
|
name: apiserver
|
|
namespace: kube-system
|
|
subjects:
|
|
- kind: User
|
|
name: apiserver
|
|
apiGroup: rbac.authorization.k8s.io
|
|
roleRef:
|
|
kind: ClusterRole
|
|
name: apiserver
|
|
apiGroup: rbac.authorization.k8s.io
|