Skip to content

Commit 6a70dfe

Browse files
author
Martin Linkhorst
committed
register rolebinding admitter in order to reject certain rolebindings
1 parent f7a7a64 commit 6a70dfe

File tree

1 file changed

+13
-0
lines changed

1 file changed

+13
-0
lines changed

cluster/manifests/01-admission-control/teapot.yaml

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -252,3 +252,16 @@ webhooks:
252252
apiGroups: [""]
253253
apiVersions: ["v1"]
254254
resources: ["services"]
255+
- name: rolebinding-admitter.teapot.zalan.do
256+
clientConfig:
257+
url: "https://localhost:8085/rolebinding"
258+
caBundle: "{{ .Cluster.ConfigItems.ca_cert_decompressed }}"
259+
admissionReviewVersions: ["v1beta1"]
260+
failurePolicy: Fail
261+
sideEffects: "NoneOnDryRun"
262+
matchPolicy: Equivalent
263+
rules:
264+
- operations: [ "CREATE", "UPDATE" ]
265+
apiGroups: ["rbac.authorization.k8s.io"]
266+
apiVersions: ["v1"]
267+
resources: ["rolebindings", "clusterrolebindings"]

0 commit comments

Comments
 (0)