From 6185e842b59b325e72453a31e30f94d67fac6c7b Mon Sep 17 00:00:00 2001 From: Quinn Murphy Date: Wed, 17 May 2017 19:27:10 -0400 Subject: [PATCH] Adding fission-rbac.yml for (#183) Set up RBAC role bindings to allow fission to create pods in the fission-function namespace. --- fission-rbac.yaml | 174 ++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 174 insertions(+) create mode 100644 fission-rbac.yaml diff --git a/fission-rbac.yaml b/fission-rbac.yaml new file mode 100644 index 00000000..f33993d7 --- /dev/null +++ b/fission-rbac.yaml @@ -0,0 +1,174 @@ +apiVersion: v1 +kind: Namespace +metadata: + name: fission + labels: + name: fission +--- +apiVersion: v1 +kind: Namespace +metadata: + name: fission-function + labels: + name: fission-function +--- +apiVersion: v1 +kind: ServiceAccount +metadata: + name: fission-svc + namespace: fission +--- +kind: RoleBinding +apiVersion: rbac.authorization.k8s.io/v1alpha1 +metadata: + name: fission-admin + namespace: fission +subjects: + - kind: ServiceAccount + name: fission-svc + namespace: fission +roleRef: + kind: ClusterRole + name: admin + apiGroup: rbac.authorization.k8s.io +--- +kind: RoleBinding +apiVersion: rbac.authorization.k8s.io/v1alpha1 +metadata: + name: fission-function-admin + namespace: fission-function +subjects: + - kind: ServiceAccount + name: fission-svc + namespace: fission +roleRef: + kind: ClusterRole + name: admin + apiGroup: rbac.authorization.k8s.io +--- +apiVersion: extensions/v1beta1 +kind: Deployment +metadata: + name: controller + namespace: fission +spec: + replicas: 1 + template: + metadata: + labels: + svc: controller + spec: + containers: + - name: controller + image: fission/fission-bundle:alpha20170328 + command: ["/fission-bundle"] + args: ["--controllerPort", "8888", "--filepath", "/filestore"] + serviceAccountName: fission-svc +--- +apiVersion: extensions/v1beta1 +kind: Deployment +metadata: + name: router + namespace: fission +spec: + replicas: 1 + template: + metadata: + labels: + svc: router + spec: + containers: + - name: router + image: fission/fission-bundle:alpha20170328 + command: ["/fission-bundle"] + args: ["--routerPort", "8888"] + serviceAccountName: fission-svc +--- +apiVersion: v1 +kind: Service +metadata: + name: poolmgr + namespace: fission + labels: + svc: poolmgr +spec: + ports: + - port: 80 + targetPort: 8888 + selector: + svc: poolmgr +--- +apiVersion: extensions/v1beta1 +kind: Deployment +metadata: + name: poolmgr + namespace: fission +spec: + replicas: 1 + template: + metadata: + labels: + svc: poolmgr + spec: + containers: + - name: poolmgr + image: fission/fission-bundle:alpha20170328 + command: ["/fission-bundle"] + args: ["--poolmgrPort", "8888"] + serviceAccountName: fission-svc +--- +apiVersion: extensions/v1beta1 +kind: Deployment +metadata: + name: kubewatcher + namespace: fission +spec: + replicas: 1 + template: + metadata: + labels: + svc: kubewatcher + spec: + containers: + - name: kubewatcher + image: fission/fission-bundle:alpha20170328 + command: ["/fission-bundle"] + args: ["--kubewatcher"] + serviceAccountName: fission-svc +--- +apiVersion: v1 +kind: Service +metadata: + name: etcd + namespace: fission + labels: + svc: etcd +spec: + ports: + - port: 2379 + targetPort: 2379 + selector: + svc: etcd +--- +apiVersion: extensions/v1beta1 +kind: Deployment +metadata: + name: etcd + namespace: fission +spec: + replicas: 1 + template: + metadata: + labels: + svc: etcd + spec: + containers: + - name: etcd + image: quay.io/coreos/etcd + imagePullPolicy: IfNotPresent + env: + - name: ETCD_LISTEN_CLIENT_URLS + value: http://0.0.0.0:2379 + - name: ETCD_ADVERTISE_CLIENT_URLS + value: http://etcd:2379 + serviceAccountName: fission-svc