Skip to content

Instantly share code, notes, and snippets.

@guilhem
Created July 2, 2019 15:57
Show Gist options
  • Save guilhem/dbb51124a290999b8a4335d0c8cb50e5 to your computer and use it in GitHub Desktop.
Save guilhem/dbb51124a290999b8a4335d0c8cb50e5 to your computer and use it in GitHub Desktop.
less intrusive rancher admin globalrole
apiVersion: management.cattle.io/v3
description: ""
displayName: Secured Admin
kind: GlobalRole
metadata:
name: secured-admin
newUserDefault: false
rules:
- apiGroups:
- management.cattle.io
resources:
- preferences
verbs:
- '*'
- apiGroups:
- management.cattle.io
resources:
- settings
verbs:
- get
- list
- watch
- apiGroups:
- management.cattle.io
resources:
- templates
- templateversions
- catalogs
verbs:
- get
- list
- watch
- apiGroups:
- management.cattle.io
resources:
- nodetemplates
verbs:
- '*'
- apiGroups:
- '*'
resources:
- secrets
verbs:
- create
- apiGroups:
- management.cattle.io
resources:
- multiclusterapps
- globaldnses
- globaldnsproviders
verbs:
- create
- apiGroups:
- project.cattle.io
resources:
- sourcecodecredentials
verbs:
- '*'
- apiGroups:
- project.cattle.io
resources:
- sourcecoderepositories
verbs:
- '*'
- apiGroups:
- management.cattle.io
resources:
- etcdbackups
verbs:
- get
- list
- watch
- apiGroups:
- management.cattle.io
resources:
- authconfigs
verbs:
- get
- list
- watch
- update
- apiGroups:
- management.cattle.io
resources:
- clusters
verbs:
- create
- list
- apiGroups:
- '*'
resources:
- secrets
verbs:
- create
- apiGroups:
- management.cattle.io
resources:
- etcdbackups
verbs:
- get
- list
- watch
- apiGroups:
- management.cattle.io
resources:
- kontainerdrivers
verbs:
- '*'
- apiGroups:
- management.cattle.io
resources:
- nodedrivers
verbs:
- '*'
- apiGroups:
- management.cattle.io
resources:
- podsecuritypolicytemplates
verbs:
- '*'
- apiGroups:
- management.cattle.io
resources:
- settings
verbs:
- '*'
- apiGroups:
- management.cattle.io
resources:
- users
- globalrolebindings
- globalroles
- roletemplates
- userattributes
verbs:
- '*'
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment