aboutsummaryrefslogtreecommitdiff
path: root/rbac-namespace-default/pod-labler.yml
diff options
context:
space:
mode:
Diffstat (limited to 'rbac-namespace-default/pod-labler.yml')
-rw-r--r--rbac-namespace-default/pod-labler.yml9
1 files changed, 4 insertions, 5 deletions
diff --git a/rbac-namespace-default/pod-labler.yml b/rbac-namespace-default/pod-labler.yml
index 78816a3..92745af 100644
--- a/rbac-namespace-default/pod-labler.yml
+++ b/rbac-namespace-default/pod-labler.yml
@@ -1,10 +1,9 @@
# To see if init containers need RBAC:
#
-# $ kubectl exec kafka-0 -- cat /etc/kafka/server.properties | grep broker.rack
-# #init#broker.rack=# zone lookup failed, see -c init-config logs
-# $ kubectl logs -c init-config kafka-0
-# ++ kubectl get node some-node '-o=go-template={{index .metadata.labels "failure-domain.beta.kubernetes.io/zone"}}'
-# Error from server (Forbidden): User "system:serviceaccount:kafka:default" cannot get nodes at the cluster scope.: "Unknown user \"system:serviceaccount:kafka:default\""
+# $ kubectl -n kafka logs kafka-2 -c init-config
+# ...
+# + kubectl -n kafka label pod kafka-2 kafka-broker-id=2
+# Error from server (Forbidden): pods "kafka-2" is forbidden: User "system:serviceaccount:kafka:default" cannot get pods in the namespace "kafka": Unknown user "system:serviceaccount:kafka:default"
#
---
kind: Role