diff --git a/adhoc-config/links-iam.yaml b/adhoc-config/links-iam.yaml new file mode 100644 index 0000000..75c0d32 --- /dev/null +++ b/adhoc-config/links-iam.yaml @@ -0,0 +1,29 @@ +# Role in the ingress-nginx namespace granting read access to pod logs +apiVersion: rbac.authorization.k8s.io/v1 +kind: Role +metadata: + name: links-log-reader + namespace: ingress-nginx +rules: + - apiGroups: [""] + resources: ["pods"] + verbs: ["list", "get"] + - apiGroups: [""] + resources: ["pods/log"] + verbs: ["get"] + +--- +# Bind the Role to the links ServiceAccount (cross-namespace) +apiVersion: rbac.authorization.k8s.io/v1 +kind: RoleBinding +metadata: + name: links-log-reader + namespace: ingress-nginx +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: Role + name: links-log-reader +subjects: + - kind: ServiceAccount + name: links + namespace: apps