1
0
Fork 0
mirror of https://github.com/kyverno/kyverno.git synced 2025-03-30 19:35:06 +00:00

fix: harden cleanup controller rbac (#7626)

Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
This commit is contained in:
Charles-Edouard Brétéché 2023-06-21 14:53:48 +02:00 committed by GitHub
parent 48d64bd031
commit 511e9fefaf
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
3 changed files with 26 additions and 28 deletions

View file

@ -42,17 +42,9 @@ rules:
resources:
- clustercleanuppolicies
- cleanuppolicies
- clustercleanuppolicies/*
- cleanuppolicies/*
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- deletecollection
- apiGroups:
- batch
resources:
@ -65,14 +57,14 @@ rules:
- update
- watch
- apiGroups:
- ''
- events.k8s.io
- ''
- events.k8s.io
resources:
- events
- events
verbs:
- create
- patch
- update
- create
- patch
- update
- apiGroups:
- authorization.k8s.io
resources:

View file

@ -35,9 +35,16 @@ rules:
- leases
verbs:
- create
- apiGroups:
- coordination.k8s.io
resources:
- leases
verbs:
- delete
- get
- patch
- update
resourceNames:
- kyverno-cleanup-controller
{{- end -}}
{{- end -}}

View file

@ -37888,17 +37888,9 @@ rules:
resources:
- clustercleanuppolicies
- cleanuppolicies
- clustercleanuppolicies/*
- cleanuppolicies/*
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- deletecollection
- apiGroups:
- batch
resources:
@ -37911,14 +37903,14 @@ rules:
- update
- watch
- apiGroups:
- ''
- events.k8s.io
- ''
- events.k8s.io
resources:
- events
- events
verbs:
- create
- patch
- update
- create
- patch
- update
- apiGroups:
- authorization.k8s.io
resources:
@ -38423,10 +38415,17 @@ rules:
- leases
verbs:
- create
- apiGroups:
- coordination.k8s.io
resources:
- leases
verbs:
- delete
- get
- patch
- update
resourceNames:
- kyverno-cleanup-controller
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role