Browse Source

修改bug

yjp 1 year ago
parent
commit
64fd4e42bf
2 changed files with 2 additions and 19 deletions
  1. 0 2
      test/token/delete_token.sh
  2. 2 17
      test/token/generate_token.sh

+ 0 - 2
test/token/delete_token.sh

@@ -1,5 +1,3 @@
 #!/bin/sh
 kubectl delete secret argo-api.service-account-token -n argo-api
 kubectl delete rolebinding argo-api -n argo-api
-kubectl delete sa argo-api -n argo-api
-kubectl delete role argo-api -n argo-api

+ 2 - 17
test/token/generate_token.sh

@@ -1,20 +1,5 @@
 #!/bin/sh
-kubectl apply -n argo-api -f - <<EOF
-apiVersion: rbac.authorization.k8s.io/v1
-kind: Role
-metadata:
-  name: argo-api
-rules:
-  - apiGroups: [""]
-    resources: ["pods"]
-    verbs: ["get", "list", "watch", "create", "delete", "update", "patch"]
-  - apiGroups: ["argoproj.io"]
-    resources: ["workflows"]
-    verbs: ["list", "update"]
-EOF
-
-kubectl create sa argo-api --namespace=argo-api
-kubectl create rolebinding argo-api --role=argo-api --serviceaccount=argo:argo-api --namespace=argo-api
+kubectl create rolebinding argo-api --clusterrole=admin --serviceaccount=argo-api:default --namespace=argo-api
 
 kubectl apply -n argo-api -f - <<EOF
 apiVersion: v1
@@ -22,7 +7,7 @@ kind: Secret
 metadata:
   name: argo-api.service-account-token
   annotations:
-    kubernetes.io/service-account.name: argo-api
+    kubernetes.io/service-account.name: default
 type: kubernetes.io/service-account-token
 EOF