Skip to main content
Version: v3.9.0

RoleBinding fields

Reference for kind: RoleBinding. Deploy and subjects are on Role bindings.

roleRef and subjects sit at the document root. They are not fields of spec. describe rolebinding prints this same shape.

Deploy
apiVersion: datasance.com/v3 # required, string
kind: RoleBinding # required, string
metadata:
name: alice-developer # required, string
namespace: my-ecn # no, string
roleRef: # required, object. Document root. Not under spec
kind: Role # required, string
name: developer # required, string
apiGroup: "" # no, string
subjects: # required, list. Document root. Not under spec
- kind: User # required, string. User, Group, or ServiceAccount
name: [email protected] # required, string
apiGroup: "" # no, string

metadata.namespace is the namespace you passed with -n.

Fields​

FieldRequiredDescription
metadata.nameYesBinding name. Unique in the namespace.
roleRefYesThe Role to grant. Root field.
roleRef.kindYesRole.
roleRef.nameYesmetadata.name of the Role.
roleRef.apiGroupNoAPI group of the Role reference.
subjectsYesWho receives the Role. Root field.
subjects[].kindYesUser, Group, or ServiceAccount.
subjects[].nameYesLogin name, identity provider role name, or ServiceAccount metadata.name.
subjects[].apiGroupNoAPI group of the subject.

A ServiceAccount is application-scoped, but the subject name is the account name only. metadata.applicationName is set on the ServiceAccount.

Deploy​

StateCLI
Name missingCreate with roleRef and subjects.
Name presentUpdate. The new roleRef and subjects replace the stored values.
Group 3See anything wrong with the document? Help us improve it!