sylvia
我使用 BuiltinRole 新增了 workspace default role,但是它的權限我直接寫入沒有反應,請問我應該怎麼去修改權限呢 謝謝
apiVersion: iam.kubesphere.io/v1beta1
kind: BuiltinRole
metadata:
annotations:
kubectl.kubernetes.io/last-applied-configuration: >
{"apiVersion":"iam.kubesphere.io/v1beta1","kind":"BuiltinRole","metadata":{"annotations":{"meta.helm.sh/release-name":"ks-core","meta.helm.sh/release-namespace":"kubesphere-system"},"labels":{"app.kubernetes.io/managed-by":"Helm","iam.kubesphere.io/scope":"workspace"},"name":"workspace-devops-member"},"role":{"aggregationRoleTemplates":{"roleSelector":{"matchLabels":{"iam.kubesphere.io/aggregate-to-devopsmem":"","iam.kubesphere.io/scope":"workspace"}},"templateNames":["workspace-view-projects","workspace-view-members","workspace-view-roles","workspace-view-groups","workspace-view-workspace-settings"]},"apiVersion":"iam.kubesphere.io/v1beta1","kind":"WorkspaceRole","metadata":{"annotations":{"iam.kubesphere.io/auto-aggregate":"true","kubesphere.io/creator":"system","kubesphere.io/description":"{\"zh\":
\"僅能新增DevOps Project\", \"en\": \"Only allow create CI
Project\"}"},"name":"devops-member"},"rules":[{"apiGroups":["*"],"resources":["*"],"verbs":["get","list","watch"]}]}}
meta.helm.sh/release-name: ks-core
meta.helm.sh/release-namespace: kubesphere-system
labels:
app.kubernetes.io/managed-by: Helm
iam.kubesphere.io/scope: workspace
name: workspace-devops-member
role:
aggregationRoleTemplates:
roleSelector:
matchLabels:
iam.kubesphere.io/aggregate-to-devopsmem: ''
iam.kubesphere.io/scope: workspace
templateNames:
- workspace-view-projects
- workspace-view-members
- workspace-view-roles
- workspace-view-groups
- workspace-view-workspace-settings
apiVersion: iam.kubesphere.io/v1beta1
kind: WorkspaceRole
metadata:
annotations:
iam.kubesphere.io/auto-aggregate: 'true'
kubesphere.io/creator: system
kubesphere.io/description: '{"zh": "僅能新增DevOps Project", "en": "Only allow create CI Project"}'
name: devops-member
rules:
- apiGroups:
- '*'
resources:
- '*'
verbs:
- get
- list
- watch