File tree 3 files changed +41
-0
lines changed
deploy/kubernetes/base/controller
3 files changed +41
-0
lines changed Original file line number Diff line number Diff line change @@ -152,6 +152,29 @@ roleRef:
152
152
kind : ClusterRole
153
153
name : csi-gce-pd-resizer-role
154
154
apiGroup : rbac.authorization.k8s.io
155
+ ---
156
+ kind : ClusterRole
157
+ apiVersion : rbac.authorization.k8s.io/v1
158
+ metadata :
159
+ name : csi-gce-pd-controller-deploy
160
+ rules :
161
+ - apiGroups : ["policy"]
162
+ resources : ["podsecuritypolicies"]
163
+ verbs : ["use"]
164
+ resourceNames :
165
+ - csi-gce-pd-controller-psp
166
+ ---
167
+ apiVersion : rbac.authorization.k8s.io/v1
168
+ kind : ClusterRoleBinding
169
+ metadata :
170
+ name : csi-gce-pd-controller-deploy
171
+ roleRef :
172
+ apiGroup : rbac.authorization.k8s.io
173
+ kind : ClusterRole
174
+ name : csi-gce-pd-controller-deploy
175
+ subjects :
176
+ - kind : ServiceAccount
177
+ name : csi-gce-pd-controller-sa
155
178
156
179
---
157
180
Original file line number Diff line number Diff line change @@ -6,3 +6,4 @@ resources:
6
6
- cluster_setup.yaml
7
7
- controller.yaml
8
8
- csidriver_info.yaml
9
+ - psp.yaml
Original file line number Diff line number Diff line change
1
+ apiVersion : policy/v1beta1
2
+ kind : PodSecurityPolicy
3
+ metadata :
4
+ name : csi-gce-pd-controller-psp
5
+ spec :
6
+ seLinux :
7
+ rule : RunAsAny
8
+ supplementalGroups :
9
+ rule : RunAsAny
10
+ runAsUser :
11
+ rule : RunAsAny
12
+ fsGroup :
13
+ rule : RunAsAny
14
+ volumes :
15
+ - " emptyDir"
16
+ - " secret"
17
+ hostNetwork : true
You can’t perform that action at this time.
0 commit comments