permissions

This commit is contained in:
Danijel Simeunovic
2026-03-06 09:15:19 +01:00
parent 671ae6e702
commit cc69346de9

View File

@@ -1,16 +1,19 @@
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole kind: ClusterRole
metadata: metadata:
name: kyverno:secrets:view name: kyverno:resources:view
labels: labels:
rbac.kyverno.io/aggregate-to-admission-controller: "true" rbac.kyverno.io/aggregate-to-admission-controller: "true"
rbac.kyverno.io/aggregate-to-reports-controller: "true" rbac.kyverno.io/aggregate-to-reports-controller: "true"
rbac.kyverno.io/aggregate-to-background-controller: "true" rbac.kyverno.io/aggregate-to-background-controller: "true"
rbac.kyverno.io/aggregate-to-cleanup-controller: "true"
rules: rules:
- apiGroups: - apiGroups:
- '' - ''
resources: resources:
- secrets - secrets
- pod
- replicaset
verbs: verbs:
- get - get
- list - list
@@ -22,11 +25,14 @@ metadata:
name: kyverno:secrets:manage name: kyverno:secrets:manage
labels: labels:
rbac.kyverno.io/aggregate-to-background-controller: "true" rbac.kyverno.io/aggregate-to-background-controller: "true"
rbac.kyverno.io/aggregate-to-cleanup-controller: "true"
rules: rules:
- apiGroups: - apiGroups:
- '' - ''
resources: resources:
- secrets - secrets
- pod
- replicaset
verbs: verbs:
- create - create
- update - update