mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-09-30 15:29:56 +02:00
Submit RBAC credentials during initial Event processing (#344)
* During initial Event processing submit the service account for pods and bind it to a cluster role that allows Patroni to successfully start. The cluster role is assumed to be created by the k8s cluster administrator.
This commit is contained in:
@@ -90,13 +90,13 @@ namespace. The operator performs **no** further syncing of this account.
|
||||
|
||||
## Role-based access control for the operator
|
||||
|
||||
The `manifests/operator-rbac.yaml` defines cluster roles and bindings needed
|
||||
The `manifests/operator-service-account-rbac.yaml` defines cluster roles and bindings needed
|
||||
for the operator to function under access control restrictions. To deploy the
|
||||
operator with this RBAC policy use:
|
||||
|
||||
```bash
|
||||
$ kubectl create -f manifests/configmap.yaml
|
||||
$ kubectl create -f manifests/operator-rbac.yaml
|
||||
$ kubectl create -f manifests/operator-service-account-rbac.yaml
|
||||
$ kubectl create -f manifests/postgres-operator.yaml
|
||||
$ kubectl create -f manifests/minimal-postgres-manifest.yaml
|
||||
```
|
||||
|
||||
@@ -110,8 +110,10 @@ configuration they are grouped under the `kubernetes` key.
|
||||
* **pod_service_account_definition**
|
||||
The operator tries to create the pod Service Account in the namespace that
|
||||
doesn't define such an account using the YAML definition provided by this
|
||||
option. If not defined, a simple definition that contains only the name will
|
||||
be used. The default is empty.
|
||||
option. If not defined, a simple definition that contains only the name will be used. The default is empty.
|
||||
|
||||
* **pod_service_account_role_binding_definition**
|
||||
This definition must bind pod service account to a role with permission sufficient for the pods to start and for Patroni to access k8s endpoints; service account on its own lacks any such rights starting with k8s v1.8. If not excplicitly defined by the user, a simple definition that binds the account to the operator's own 'zalando-postgres-operator' cluster role will be used. The default is empty.
|
||||
|
||||
* **pod_terminate_grace_period**
|
||||
Patroni pods are [terminated
|
||||
|
||||
Reference in New Issue
Block a user