File tree Expand file tree Collapse file tree 3 files changed +42
-0
lines changed
deploy/kubernetes/base/controller Expand file tree Collapse file tree 3 files changed +42
-0
lines changed Original file line number Diff line number Diff line change @@ -152,6 +152,29 @@ roleRef:
152152 kind : ClusterRole
153153 name : csi-gce-pd-resizer-role
154154 apiGroup : rbac.authorization.k8s.io
155+ ---
156+ kind : ClusterRole
157+ apiVersion : rbac.authorization.k8s.io/v1
158+ metadata :
159+ name : csi-gce-pd-controller-deploy
160+ rules :
161+ - apiGroups : ["policy"]
162+ resources : ["podsecuritypolicies"]
163+ verbs : ["use"]
164+ resourceNames :
165+ - csi-gce-pd-controller-psp
166+ ---
167+ apiVersion : rbac.authorization.k8s.io/v1
168+ kind : ClusterRoleBinding
169+ metadata :
170+ name : csi-gce-pd-controller-deploy
171+ roleRef :
172+ apiGroup : rbac.authorization.k8s.io
173+ kind : ClusterRole
174+ name : csi-gce-pd-controller-deploy
175+ subjects :
176+ - kind : ServiceAccount
177+ name : csi-gce-pd-controller-sa
155178
156179---
157180
Original file line number Diff line number Diff line change @@ -6,3 +6,4 @@ resources:
66- cluster_setup.yaml
77- controller.yaml
88- csidriver_info.yaml
9+ - psp.yaml
Original file line number Diff line number Diff line change 1+ apiVersion : policy/v1beta1
2+ kind : PodSecurityPolicy
3+ metadata :
4+ name : csi-gce-pd-controller-psp
5+ spec :
6+ seLinux :
7+ rule : RunAsAny
8+ supplementalGroups :
9+ rule : RunAsAny
10+ runAsUser :
11+ rule : RunAsAny
12+ fsGroup :
13+ rule : RunAsAny
14+ volumes :
15+ - " configMap"
16+ - " emptyDir"
17+ - " secret"
18+ hostNetwork : true
You can’t perform that action at this time.
0 commit comments