Browse Source

split roles

main
Nicolas Massé 4 years ago
parent
commit
aedf5cc0cc
  1. 14
      cicd/03-rolebindings.yaml
  2. 13
      deployment/03-rolebindings.yaml

14
cicd/03-rolebindings.yaml

@ -11,17 +11,3 @@ subjects:
- kind: ServiceAccount
name: default
namespace: vulnerable-log4j
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: cicd-can-admin-this-namespace
namespace: vulnerable-log4j
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: edit
subjects:
- kind: ServiceAccount
name: pipeline
namespace: vulnerable-cicd

13
deployment/03-rolebindings.yaml

@ -0,0 +1,13 @@
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: cicd-can-admin-this-namespace
namespace: vulnerable-log4j
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: edit
subjects:
- kind: ServiceAccount
name: pipeline
namespace: vulnerable-cicd
Loading…
Cancel
Save