ServiceAccount fields
Reference for kind: ServiceAccount. Deploy and the application/name CLI form are on Service accounts.
The identity is the pair (metadata.applicationName, metadata.name). roleRef sits at the document root. It is not a field of spec. describe serviceaccount prints this same shape.
Deploy
apiVersion: datasance.com/v3 # required, string
kind: ServiceAccount # required, string
metadata:
name: worker # required, string
namespace: my-ecn # no, string
applicationName: my-app # required, string
roleRef: # required, object. Document root. Not under spec
kind: Role # required, string
name: app-worker # required, string
apiGroup: "" # no, string
metadata.namespace is the namespace you passed with -n. metadata.applicationName must match an Application metadata.name.
The microservice field spec.serviceAccount.roleRef is a different object. It lives under the microservice spec. See Microservice fields.
Fields
| Field | Required | Description |
|---|---|---|
metadata.name | Yes | Account name inside the application. |
metadata.applicationName | Yes | Application that owns this account. |
roleRef.kind | Yes | Role. |
roleRef.name | Yes | Role metadata.name. |
roleRef.apiGroup | No | Passed through to the Controller. |
A RoleBinding subject that grants this account uses metadata.name only, not application/name.
Deploy
| State | CLI |
|---|---|
Pair (applicationName, name) missing | Create with roleRef. |
| Pair present | Update roleRef. |
| Condition | Result |
|---|---|
Empty applicationName | CLI error. The account must have applicationName. |
| No Controller in the namespace | CLI error. |
describe and delete take application/name.
See anything wrong with the document? Help us improve it!