Skip to main content
Version: v3.9.0

ServiceAccount fields

Reference for kind: ServiceAccount. Deploy and the application/name CLI form are on Service accounts.

The identity is the pair (metadata.applicationName, metadata.name). roleRef sits at the document root. It is not a field of spec. describe serviceaccount prints this same shape.

Deploy
apiVersion: datasance.com/v3 # required, string
kind: ServiceAccount # required, string
metadata:
name: worker # required, string
namespace: my-ecn # no, string
applicationName: my-app # required, string
roleRef: # required, object. Document root. Not under spec
kind: Role # required, string
name: app-worker # required, string
apiGroup: "" # no, string

metadata.namespace is the namespace you passed with -n. metadata.applicationName must match an Application metadata.name.

The microservice field spec.serviceAccount.roleRef is a different object. It lives under the microservice spec. See Microservice fields.

Fields​

FieldRequiredDescription
metadata.nameYesAccount name inside the application.
metadata.applicationNameYesApplication that owns this account.
roleRef.kindYesRole.
roleRef.nameYesRole metadata.name.
roleRef.apiGroupNoPassed through to the Controller.

A RoleBinding subject that grants this account uses metadata.name only, not application/name.

Deploy​

StateCLI
Pair (applicationName, name) missingCreate with roleRef.
Pair presentUpdate roleRef.
ConditionResult
Empty applicationNameCLI error. The account must have applicationName.
No Controller in the namespaceCLI error.

describe and delete take application/name.

Group 3See anything wrong with the document? Help us improve it!