[Kubernetes] ServiceAccount, Role, RoleBinding ๊ด๊ณ
- ServiceAccount : ๊ถํ์ ์ฌ์ฉํ ์ฃผ์ฒด
- Role : ์ด๋ค ๋ฆฌ์์ค์ ์ด๋ค ํ๋์ ํ ์ ์๋์ง ์ ์
- RoleBinding: ServiceAccount์ Role์ ์ฐ๊ฒฐ
apiVersion: v1
kind: ServiceAccount
metadata:
name: app-sa
namespace: dev
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
namespace: dev
name: pod-reader
rules:
- apiGroups: [""]
resources: ["pods"]
verbs: ["get", "list", "watch"]
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: read-pods
namespace: dev
subjects:
- kind: ServiceAccount
name: app-sa
namespace: dev
roleRef:
kind: Role
name: pod-reader
apiGroup: rbac.authorization.k8s.io
Role : ํน์ namespace ๋ฒ์, ํน์ namespace ์์์๋ง ๋์
ClusterRole: Node ์กฐํ, ๋ชจ๋ namespace pod ์กฐํ
| RoleBinding | namespace |
| ClusterRoleBinding | cluster ์ ์ฒด |