openstack-helm-infra/prometheus/templates
Tin Lam 628fd3007d RBAC: Consolidate serviceaccounts and restrict rbac
Currently, services have two serviceaccounts: one specified in the
chart that cannot read anything, and one injected via helm-toolkit
that can read everything. This patch set refactors the logic to:

- cleanup the roles and their binding automatically when the helm
  chart is deleted;
- remove the need to separately mount a serviceaccount  with secret;
- better handling of namespaces resource restriction.

Co-Authored-By: portdirect <pete@port.direct>

Change-Id: I47d41e0cad9b5b002f59fc9652bad2cc025538dc
2017-12-19 20:22:57 -05:00
..
bin Update Prometheus to version 2.0 2017-12-17 20:47:09 +00:00
clusterrole.yaml Prometheus monitoring for OSH infra 2017-11-30 09:43:17 -06:00
clusterrolebinding.yaml RBAC: Consolidate serviceaccounts and restrict rbac 2017-12-19 20:22:57 -05:00
configmap-bin.yaml Prometheus monitoring for OSH infra 2017-11-30 09:43:17 -06:00
configmap-etc.yaml Prometheus monitoring for OSH infra 2017-11-30 09:43:17 -06:00
configmap-rules.yaml Prometheus monitoring for OSH infra 2017-11-30 09:43:17 -06:00
ingress-prometheus.yaml Prometheus monitoring for OSH infra 2017-11-30 09:43:17 -06:00
job-image-repo-sync.yaml RBAC: Consolidate serviceaccounts and restrict rbac 2017-12-19 20:22:57 -05:00
pod-helm-tests.yaml RBAC: Consolidate serviceaccounts and restrict rbac 2017-12-19 20:22:57 -05:00
pvc.yaml Prometheus monitoring for OSH infra 2017-11-30 09:43:17 -06:00
service-ingress-prometheus.yaml Prometheus monitoring for OSH infra 2017-11-30 09:43:17 -06:00
service.yaml Gather deployment information after checks run 2017-12-11 09:57:28 -06:00
statefulset.yaml RBAC: Consolidate serviceaccounts and restrict rbac 2017-12-19 20:22:57 -05:00