forked from rook/rook
In order to help users check that they have implemented the newly-added Multus host configuration prerequisites, add a check to the validation tool to verify connectivity. Because users who are already running clusters with Multus enabled, add a flag that allows users to only check for host configuration prerequisites. This mode will not start the large number of clients that would normally be started because those clients could disrupt a running Rook cluster negatively. Host checking pods require host network access. Many Kubernetes distributions have pod security features enabled. In order to allow non-Vanilla distros to run this tool, allow specifying a service account that pods will run as, which can be configured by the admin to allow test pods. Signed-off-by: Blaine Gardner <blaine.gardner@ibm.com>
39 lines
933 B
YAML
39 lines
933 B
YAML
# ServiceAccount and RBAC to support running multus validation test on OpenShift
|
|
# Deploy these resources, then use `serviceAccountName: multus-validation-test` in the validation
|
|
# test config file.
|
|
---
|
|
apiVersion: v1
|
|
kind: ServiceAccount
|
|
metadata:
|
|
name: multus-validation-test
|
|
namespace: openshift-storage
|
|
---
|
|
apiVersion: rbac.authorization.k8s.io/v1
|
|
kind: Role
|
|
metadata:
|
|
name: multus-validation-test
|
|
namespace: openshift-storage
|
|
rules:
|
|
- apiGroups:
|
|
- security.openshift.io
|
|
resourceNames:
|
|
- hostnetwork-v2
|
|
resources:
|
|
- securitycontextconstraints
|
|
verbs:
|
|
- use
|
|
---
|
|
apiVersion: rbac.authorization.k8s.io/v1
|
|
kind: RoleBinding
|
|
metadata:
|
|
name: multus-validation-test
|
|
namespace: openshift-storage
|
|
roleRef:
|
|
apiGroup: rbac.authorization.k8s.io
|
|
kind: Role
|
|
name: multus-validation-test
|
|
subjects:
|
|
- kind: ServiceAccount
|
|
name: multus-validation-test
|
|
namespace: openshift-storage
|