1
0
Fork 0
mirror of https://github.com/kubernetes-sigs/node-feature-discovery.git synced 2025-03-17 22:08:33 +00:00
node-feature-discovery/deployment/base/rbac
adrianc 3f012c2d5a
Add support running with OwnerReferencesPermissionEnforcement
when OwnerReferencesPermissionEnforcement validating webhook is
enabled additional permissions are required to set/update owner ref
field. NFD worker sets/updates NodeFeature owner ref field to
the worker pod and owning daemonset.

owner reference can only be updated if the worker has delete permissions
for NodeFeatures.

if owner reference has blockOwnerDeletion (as the case for the daemonset
owner reference) then it requires update permissions to the finalizers
of the owner, to avoid this, we set blockOwnerDeleteion to false for all
owners referenced from NFD worker pod when setting/updating NodeFeature
owner ref.

Signed-off-by: adrianc <adrianc@nvidia.com>
2025-01-08 13:44:30 +02:00
..
kustomization.yaml nfd-worker: support creating NodeFeatures object 2022-12-14 07:31:28 +02:00
master-clusterrole.yaml deploy: add CR restrictions to the helm config 2024-09-16 16:02:42 +02:00
master-clusterrolebinding.yaml deployment: add kustomize base 2021-08-18 14:05:57 +03:00
master-serviceaccount.yaml deployment: add kustomize base 2021-08-18 14:05:57 +03:00
worker-role.yaml Add support running with OwnerReferencesPermissionEnforcement 2025-01-08 13:44:30 +02:00
worker-rolebinding.yaml nfd-worker: support creating NodeFeatures object 2022-12-14 07:31:28 +02:00
worker-serviceaccount.yaml nfd-worker: support creating NodeFeatures object 2022-12-14 07:31:28 +02:00