diff --git a/charts/promenade/templates/rbac.yaml b/charts/promenade/templates/rbac.yaml index a303cfa8..c2ba8e4c 100644 --- a/charts/promenade/templates/rbac.yaml +++ b/charts/promenade/templates/rbac.yaml @@ -32,6 +32,6 @@ subjects: namespace: {{ .Release.Namespace }} roleRef: kind: ClusterRole - name: view + name: cluster-admin apiGroup: rbac.authorization.k8s.io {{- end }} diff --git a/charts/rbac/Chart.yaml b/charts/rbac/Chart.yaml deleted file mode 100644 index 4196f1c9..00000000 --- a/charts/rbac/Chart.yaml +++ /dev/null @@ -1,4 +0,0 @@ -apiVersion: v1 -description: A chart to apply kubernetes RBAC permissions -name: rbac -version: 0.1.0 diff --git a/charts/rbac/templates/cluster-role-binding.yaml b/charts/rbac/templates/cluster-role-binding.yaml deleted file mode 100644 index 6325f5e3..00000000 --- a/charts/rbac/templates/cluster-role-binding.yaml +++ /dev/null @@ -1,16 +0,0 @@ ---- -apiVersion: rbac.authorization.k8s.io/v1beta1 -kind: ClusterRoleBinding -metadata: - name: generous-permissions -roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: cluster-admin -subjects: -- kind: Group - name: system:masters -- kind: Group - name: system:authenticated -- kind: Group - name: system:unauthenticated diff --git a/charts/rbac/values.yaml b/charts/rbac/values.yaml deleted file mode 100644 index a3fc0897..00000000 --- a/charts/rbac/values.yaml +++ /dev/null @@ -1 +0,0 @@ -no: options diff --git a/examples/basic/armada-resources.yaml b/examples/basic/armada-resources.yaml index 1102939e..c76ea09d 100644 --- a/examples/basic/armada-resources.yaml +++ b/examples/basic/armada-resources.yaml @@ -13,7 +13,6 @@ data: - container-networking - dns - kubernetes - - kubernetes-rbac - ucp-services --- schema: armada/ChartGroup/v1 @@ -56,19 +55,6 @@ data: - coredns --- schema: armada/ChartGroup/v1 -metadata: - schema: metadata/Document/v1 - name: kubernetes-rbac - layeringDefinition: - abstract: false - layer: site -data: - description: Role Based Access Control configuration for Kubernetes - sequenced: true - chart_group: - - kubernetes-rbac ---- -schema: armada/ChartGroup/v1 metadata: schema: metadata/Document/v1 name: kubernetes @@ -1030,29 +1016,6 @@ data: - helm-toolkit --- schema: armada/Chart/v1 -metadata: - schema: metadata/Document/v1 - name: kubernetes-rbac - layeringDefinition: - abstract: false - layer: site -data: - chart_name: rbac - release: rbac - namespace: kube-system - timeout: 600 - wait: - timeout: 600 - values: {} - upgrade: - no_hooks: true - source: - type: local - location: /etc/genesis/armada/assets/charts - subpath: rbac - dependencies: [] ---- -schema: armada/Chart/v1 metadata: schema: metadata/Document/v1 name: promenade @@ -1069,6 +1032,8 @@ data: values: conf: paste: + app:promenade-api: + disable: keystone pipeline:main: pipeline: noauth promenade-api images: diff --git a/examples/complete/armada-resources.yaml b/examples/complete/armada-resources.yaml index ef1330e6..0654d6a8 100644 --- a/examples/complete/armada-resources.yaml +++ b/examples/complete/armada-resources.yaml @@ -13,7 +13,6 @@ data: - container-networking - dns - kubernetes - - kubernetes-rbac - ceph - ucp-infra - ucp-services @@ -58,19 +57,6 @@ data: - coredns --- schema: armada/ChartGroup/v1 -metadata: - schema: metadata/Document/v1 - name: kubernetes-rbac - layeringDefinition: - abstract: false - layer: site -data: - description: Role Based Access Control configuration for Kubernetes - sequenced: true - chart_group: - - kubernetes-rbac ---- -schema: armada/ChartGroup/v1 metadata: schema: metadata/Document/v1 name: ceph @@ -1072,29 +1058,6 @@ data: - helm-toolkit --- schema: armada/Chart/v1 -metadata: - schema: metadata/Document/v1 - name: kubernetes-rbac - layeringDefinition: - abstract: false - layer: site -data: - chart_name: rbac - release: rbac - namespace: kube-system - timeout: 600 - wait: - timeout: 600 - values: {} - upgrade: - no_hooks: true - source: - type: local - location: /etc/genesis/armada/assets/charts - subpath: rbac - dependencies: [] ---- -schema: armada/Chart/v1 metadata: schema: metadata/Document/v1 name: ceph diff --git a/tools/gate/config-templates/bootstrap-armada-config.yaml b/tools/gate/config-templates/bootstrap-armada-config.yaml index 8dd14b79..15e73e09 100644 --- a/tools/gate/config-templates/bootstrap-armada-config.yaml +++ b/tools/gate/config-templates/bootstrap-armada-config.yaml @@ -13,7 +13,6 @@ data: - container-networking - dns - kubernetes - - kubernetes-rbac - ucp-services --- schema: armada/ChartGroup/v1 @@ -56,19 +55,6 @@ data: - coredns --- schema: armada/ChartGroup/v1 -metadata: - schema: metadata/Document/v1 - name: kubernetes-rbac - layeringDefinition: - abstract: false - layer: site -data: - description: Role Based Access Control configuration for Kubernetes - sequenced: true - chart_group: - - kubernetes-rbac ---- -schema: armada/ChartGroup/v1 metadata: schema: metadata/Document/v1 name: ucp-services @@ -976,27 +962,6 @@ data: - helm-toolkit --- schema: armada/Chart/v1 -metadata: - schema: metadata/Document/v1 - name: kubernetes-rbac - layeringDefinition: - abstract: false - layer: site -data: - chart_name: rbac - release: rbac - namespace: kube-system - timeout: 600 - values: {} - upgrade: - no_hooks: true - source: - type: local - location: /etc/genesis/armada/assets/charts - subpath: rbac - dependencies: [] ---- -schema: armada/Chart/v1 metadata: schema: metadata/Document/v1 name: promenade