mirror of
https://github.com/kyverno/kyverno.git
synced 2025-03-30 19:35:06 +00:00
fix: harden cleanup controller rbac (#7626)
Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
This commit is contained in:
parent
48d64bd031
commit
511e9fefaf
3 changed files with 26 additions and 28 deletions
|
@ -42,17 +42,9 @@ rules:
|
|||
resources:
|
||||
- clustercleanuppolicies
|
||||
- cleanuppolicies
|
||||
- clustercleanuppolicies/*
|
||||
- cleanuppolicies/*
|
||||
verbs:
|
||||
- create
|
||||
- delete
|
||||
- get
|
||||
- list
|
||||
- patch
|
||||
- update
|
||||
- watch
|
||||
- deletecollection
|
||||
- apiGroups:
|
||||
- batch
|
||||
resources:
|
||||
|
@ -65,14 +57,14 @@ rules:
|
|||
- update
|
||||
- watch
|
||||
- apiGroups:
|
||||
- ''
|
||||
- events.k8s.io
|
||||
- ''
|
||||
- events.k8s.io
|
||||
resources:
|
||||
- events
|
||||
- events
|
||||
verbs:
|
||||
- create
|
||||
- patch
|
||||
- update
|
||||
- create
|
||||
- patch
|
||||
- update
|
||||
- apiGroups:
|
||||
- authorization.k8s.io
|
||||
resources:
|
||||
|
|
|
@ -35,9 +35,16 @@ rules:
|
|||
- leases
|
||||
verbs:
|
||||
- create
|
||||
- apiGroups:
|
||||
- coordination.k8s.io
|
||||
resources:
|
||||
- leases
|
||||
verbs:
|
||||
- delete
|
||||
- get
|
||||
- patch
|
||||
- update
|
||||
resourceNames:
|
||||
- kyverno-cleanup-controller
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
|
|
@ -37888,17 +37888,9 @@ rules:
|
|||
resources:
|
||||
- clustercleanuppolicies
|
||||
- cleanuppolicies
|
||||
- clustercleanuppolicies/*
|
||||
- cleanuppolicies/*
|
||||
verbs:
|
||||
- create
|
||||
- delete
|
||||
- get
|
||||
- list
|
||||
- patch
|
||||
- update
|
||||
- watch
|
||||
- deletecollection
|
||||
- apiGroups:
|
||||
- batch
|
||||
resources:
|
||||
|
@ -37911,14 +37903,14 @@ rules:
|
|||
- update
|
||||
- watch
|
||||
- apiGroups:
|
||||
- ''
|
||||
- events.k8s.io
|
||||
- ''
|
||||
- events.k8s.io
|
||||
resources:
|
||||
- events
|
||||
- events
|
||||
verbs:
|
||||
- create
|
||||
- patch
|
||||
- update
|
||||
- create
|
||||
- patch
|
||||
- update
|
||||
- apiGroups:
|
||||
- authorization.k8s.io
|
||||
resources:
|
||||
|
@ -38423,10 +38415,17 @@ rules:
|
|||
- leases
|
||||
verbs:
|
||||
- create
|
||||
- apiGroups:
|
||||
- coordination.k8s.io
|
||||
resources:
|
||||
- leases
|
||||
verbs:
|
||||
- delete
|
||||
- get
|
||||
- patch
|
||||
- update
|
||||
resourceNames:
|
||||
- kyverno-cleanup-controller
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
|
|
Loading…
Add table
Reference in a new issue