Skip to content

Commit 79d65fd

Browse files
committed
Details will live in the respective policies
1 parent 1c6b7bb commit 79d65fd

File tree

2 files changed

+8
-10
lines changed

2 files changed

+8
-10
lines changed

README.md

Lines changed: 0 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -59,15 +59,6 @@ For clusters that enfoce [RBAC](https://kubernetes.io/docs/admin/authorization/r
5959
kubectl apply -f rbac-namespace-default/
6060
```
6161

62-
For example here's how you see that `kafka`s init containers need RBAC for [rack awareness](https://github.com/Yolean/kubernetes-kafka/pull/41):
63-
```
64-
$ kubectl exec kafka-1 -- cat /etc/kafka/server.properties | grep broker.rack
65-
#init#broker.rack=# zone lookup failed, see -c init-config logs
66-
$ kubectl logs -c init-config kafka-0
67-
++ kubectl get node some-node '-o=go-template={{index .metadata.labels "failure-domain.beta.kubernetes.io/zone"}}'
68-
Error from server (Forbidden): User "system:serviceaccount:kafka:default" cannot get nodes at the cluster scope.: "Unknown user \"system:serviceaccount:kafka:default\""
69-
```
70-
7162
# Tests
7263

7364
```

rbac-namespace-default/node-reader.yml

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,11 @@
1-
# For kubectl get node, required for kafka init container rack awareness
1+
# To see if init containers need RBAC:
2+
#
3+
# $ kubectl exec kafka-1 -- cat /etc/kafka/server.properties | grep broker.rack
4+
# #init#broker.rack=# zone lookup failed, see -c init-config logs
5+
# $ kubectl logs -c init-config kafka-0
6+
# ++ kubectl get node some-node '-o=go-template={{index .metadata.labels "failure-domain.beta.kubernetes.io/zone"}}'
7+
# Error from server (Forbidden): User "system:serviceaccount:kafka:default" cannot get nodes at the cluster scope.: "Unknown user \"system:serviceaccount:kafka:default\""
8+
#
29
---
310
kind: ClusterRole
411
apiVersion: rbac.authorization.k8s.io/v1beta1

0 commit comments

Comments
 (0)