发布

  • Support custom RBAC resources (#572)

    frostbyte_neo 发布于 2022-01-04 07:48:22 +00:00

    Motivation: Allow users to change the default RBAC resources (ServiceAccount, ClusterRole, ClusterRoleBinding, Role and RoleBinding) without having Mizu delete them every run.

    Adds app.kubernetes.io/created-by and app.kubernetes.io/managed-by labels to all resources.
    The value of app.kubernetes.io/created-by is either mizu-cli or mizu-agent.
    The value of app.kubernetes.io/managed-by is mizu.
    When Mizu cleans resources (ctrl-c in tap cmd or mizu clean cmd) it removes all RBAC resources that have managed-by=mizu, and only those.

    A user may have a ClusterRole named mizu-clusterrole. If it doesn't have the label app.kubernetes.io/managed-by=mizu, then Mizu won't overwrite it and won't delete it.
    Other resources (deployments, services etc.) are always removed, regardless of their labels.

    下载附件