Skip to content

Commit 45ed721

Browse files
committed
ci: Add manifest for cilium v1.18
Signed-off-by: Vipul Singh <vipul21sept@gmail.com>
1 parent 0b0de54 commit 45ed721

23 files changed

+10626
-0
lines changed
Lines changed: 121 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,121 @@
1+
apiVersion: rbac.authorization.k8s.io/v1
2+
kind: ClusterRole
3+
metadata:
4+
name: cilium
5+
labels:
6+
app.kubernetes.io/part-of: cilium
7+
rules:
8+
- apiGroups:
9+
- networking.k8s.io
10+
resources:
11+
- networkpolicies
12+
verbs:
13+
- get
14+
- list
15+
- watch
16+
- apiGroups:
17+
- discovery.k8s.io
18+
resources:
19+
- endpointslices
20+
verbs:
21+
- get
22+
- list
23+
- watch
24+
- apiGroups:
25+
- ""
26+
resources:
27+
- namespaces
28+
- services
29+
- pods
30+
- endpoints
31+
- nodes
32+
verbs:
33+
- get
34+
- list
35+
- watch
36+
- apiGroups:
37+
- apiextensions.k8s.io
38+
resources:
39+
- customresourcedefinitions
40+
verbs:
41+
- list
42+
- watch
43+
# This is used when validating policies in preflight. This will need to stay
44+
# until we figure out how to avoid "get" inside the preflight, and then
45+
# should be removed ideally.
46+
- get
47+
- apiGroups:
48+
- cilium.io
49+
resources:
50+
- ciliumbgppeeringpolicies
51+
- ciliumclusterwideenvoyconfigs
52+
- ciliumclusterwidenetworkpolicies
53+
- ciliumegressgatewaypolicies
54+
- ciliumendpoints
55+
- ciliumendpointslices
56+
- ciliumenvoyconfigs
57+
- ciliumidentities
58+
- ciliumlocalredirectpolicies
59+
- ciliumnetworkpolicies
60+
- ciliumnodes
61+
- ciliumnodeconfigs
62+
- ciliumloadbalancerippools
63+
- ciliumcidrgroups
64+
- ciliuml2announcementpolicies
65+
- ciliumpodippools
66+
- ciliumbgpnodeconfigs
67+
- ciliumbgpadvertisements
68+
- ciliumbgppeerconfigs
69+
verbs:
70+
- list
71+
- watch
72+
- apiGroups:
73+
- cilium.io
74+
resources:
75+
- ciliumidentities
76+
- ciliumendpoints
77+
- ciliumnodes
78+
verbs:
79+
- create
80+
- apiGroups:
81+
- cilium.io
82+
# To synchronize garbage collection of such resources
83+
resources:
84+
- ciliumidentities
85+
verbs:
86+
- update
87+
- apiGroups:
88+
- cilium.io
89+
resources:
90+
- ciliumendpoints
91+
verbs:
92+
- delete
93+
- get
94+
- apiGroups:
95+
- cilium.io
96+
resources:
97+
- ciliumnodes
98+
- ciliumnodes/status
99+
verbs:
100+
- get
101+
- update
102+
- apiGroups:
103+
- cilium.io
104+
resources:
105+
- ciliumnetworkpolicies/status
106+
- ciliumclusterwidenetworkpolicies/status
107+
- ciliumendpoints/status
108+
- ciliumendpoints
109+
- ciliuml2announcementpolicies/status
110+
- ciliumbgpnodeconfigs/status
111+
verbs:
112+
- patch
113+
- apiGroups:
114+
- ""
115+
resourceNames:
116+
- cilium-config
117+
resources:
118+
- configmaps
119+
verbs:
120+
- list
121+
- watch
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
apiVersion: rbac.authorization.k8s.io/v1
2+
kind: ClusterRoleBinding
3+
metadata:
4+
name: cilium
5+
labels:
6+
app.kubernetes.io/part-of: cilium
7+
roleRef:
8+
apiGroup: rbac.authorization.k8s.io
9+
kind: ClusterRole
10+
name: cilium
11+
subjects:
12+
- kind: ServiceAccount
13+
name: "cilium"
14+
namespace: kube-system
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
apiVersion: v1
2+
kind: ServiceAccount
3+
metadata:
4+
name: "cilium"
5+
namespace: kube-system

0 commit comments

Comments
 (0)