From 18b59162d54553d2187e4fee96ec8f212c57f264 Mon Sep 17 00:00:00 2001 From: Stephen Finucane Date: Tue, 29 Oct 2024 18:05:54 +0000 Subject: [PATCH] assets: Remove redundant clusterrole rules These are already defined in the role and do not need to be duplicated in the cluster role. As always, the real changes are in the 'base' directory and the changes in 'generated' are auto-generated by 'make update'. While we're here, we also remove some unnecessary quotes for the source definition. Signed-off-by: Stephen Finucane --- .../aws-ebs/base/05_clusterrole.yaml | 17 ++--------------- ...ws-ebs-csi-driver-operator-clusterrole.yaml | 12 ------------ ...ws-ebs-csi-driver-operator-clusterrole.yaml | 12 ------------ .../azure-disk/base/06_clusterrole.yaml | 18 +++--------------- ...e-disk-csi-driver-operator-clusterrole.yaml | 12 ------------ ...e-disk-csi-driver-operator-clusterrole.yaml | 12 ------------ .../azure-file/base/06_clusterrole.yaml | 18 +++--------------- ...e-file-csi-driver-operator-clusterrole.yaml | 12 ------------ ...e-file-csi-driver-operator-clusterrole.yaml | 12 ------------ 9 files changed, 8 insertions(+), 117 deletions(-) diff --git a/assets/csidriveroperators/aws-ebs/base/05_clusterrole.yaml b/assets/csidriveroperators/aws-ebs/base/05_clusterrole.yaml index 06df41674..6cf0c3d97 100644 --- a/assets/csidriveroperators/aws-ebs/base/05_clusterrole.yaml +++ b/assets/csidriveroperators/aws-ebs/base/05_clusterrole.yaml @@ -280,21 +280,8 @@ rules: - watch # Allow kube-rbac-proxy to create TokenReview to be able to authenticate Prometheus when collecting metrics - apiGroups: - - "authentication.k8s.io" + - authentication.k8s.io resources: - - "tokenreviews" + - tokenreviews verbs: - - "create" -- apiGroups: - - coordination.k8s.io - resources: - - leases - verbs: - - get - - list - - watch - create - - update - - patch - - delete - diff --git a/assets/csidriveroperators/aws-ebs/hypershift/guest/generated/rbac.authorization.k8s.io_v1_clusterrole_aws-ebs-csi-driver-operator-clusterrole.yaml b/assets/csidriveroperators/aws-ebs/hypershift/guest/generated/rbac.authorization.k8s.io_v1_clusterrole_aws-ebs-csi-driver-operator-clusterrole.yaml index a8fff62be..36fb29e32 100644 --- a/assets/csidriveroperators/aws-ebs/hypershift/guest/generated/rbac.authorization.k8s.io_v1_clusterrole_aws-ebs-csi-driver-operator-clusterrole.yaml +++ b/assets/csidriveroperators/aws-ebs/hypershift/guest/generated/rbac.authorization.k8s.io_v1_clusterrole_aws-ebs-csi-driver-operator-clusterrole.yaml @@ -283,15 +283,3 @@ rules: - tokenreviews verbs: - create -- apiGroups: - - coordination.k8s.io - resources: - - leases - verbs: - - get - - list - - watch - - create - - update - - patch - - delete diff --git a/assets/csidriveroperators/aws-ebs/standalone/generated/rbac.authorization.k8s.io_v1_clusterrole_aws-ebs-csi-driver-operator-clusterrole.yaml b/assets/csidriveroperators/aws-ebs/standalone/generated/rbac.authorization.k8s.io_v1_clusterrole_aws-ebs-csi-driver-operator-clusterrole.yaml index a8fff62be..36fb29e32 100644 --- a/assets/csidriveroperators/aws-ebs/standalone/generated/rbac.authorization.k8s.io_v1_clusterrole_aws-ebs-csi-driver-operator-clusterrole.yaml +++ b/assets/csidriveroperators/aws-ebs/standalone/generated/rbac.authorization.k8s.io_v1_clusterrole_aws-ebs-csi-driver-operator-clusterrole.yaml @@ -283,15 +283,3 @@ rules: - tokenreviews verbs: - create -- apiGroups: - - coordination.k8s.io - resources: - - leases - verbs: - - get - - list - - watch - - create - - update - - patch - - delete diff --git a/assets/csidriveroperators/azure-disk/base/06_clusterrole.yaml b/assets/csidriveroperators/azure-disk/base/06_clusterrole.yaml index d273098c8..7139ee9f9 100644 --- a/assets/csidriveroperators/azure-disk/base/06_clusterrole.yaml +++ b/assets/csidriveroperators/azure-disk/base/06_clusterrole.yaml @@ -94,18 +94,6 @@ rules: - create - watch - delete -- apiGroups: - - coordination.k8s.io - resources: - - leases - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - apiGroups: - '' resources: @@ -302,8 +290,8 @@ rules: - watch # Allow kube-rbac-proxy to create TokenReview to be able to authenticate Prometheus when collecting metrics - apiGroups: - - "authentication.k8s.io" + - authentication.k8s.io resources: - - "tokenreviews" + - tokenreviews verbs: - - "create" + - create diff --git a/assets/csidriveroperators/azure-disk/hypershift/guest/generated/rbac.authorization.k8s.io_v1_clusterrole_azure-disk-csi-driver-operator-clusterrole.yaml b/assets/csidriveroperators/azure-disk/hypershift/guest/generated/rbac.authorization.k8s.io_v1_clusterrole_azure-disk-csi-driver-operator-clusterrole.yaml index 7a658ceb1..147621920 100644 --- a/assets/csidriveroperators/azure-disk/hypershift/guest/generated/rbac.authorization.k8s.io_v1_clusterrole_azure-disk-csi-driver-operator-clusterrole.yaml +++ b/assets/csidriveroperators/azure-disk/hypershift/guest/generated/rbac.authorization.k8s.io_v1_clusterrole_azure-disk-csi-driver-operator-clusterrole.yaml @@ -93,18 +93,6 @@ rules: - create - watch - delete -- apiGroups: - - coordination.k8s.io - resources: - - leases - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - apiGroups: - "" resources: diff --git a/assets/csidriveroperators/azure-disk/standalone/generated/rbac.authorization.k8s.io_v1_clusterrole_azure-disk-csi-driver-operator-clusterrole.yaml b/assets/csidriveroperators/azure-disk/standalone/generated/rbac.authorization.k8s.io_v1_clusterrole_azure-disk-csi-driver-operator-clusterrole.yaml index 7a658ceb1..147621920 100644 --- a/assets/csidriveroperators/azure-disk/standalone/generated/rbac.authorization.k8s.io_v1_clusterrole_azure-disk-csi-driver-operator-clusterrole.yaml +++ b/assets/csidriveroperators/azure-disk/standalone/generated/rbac.authorization.k8s.io_v1_clusterrole_azure-disk-csi-driver-operator-clusterrole.yaml @@ -93,18 +93,6 @@ rules: - create - watch - delete -- apiGroups: - - coordination.k8s.io - resources: - - leases - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - apiGroups: - "" resources: diff --git a/assets/csidriveroperators/azure-file/base/06_clusterrole.yaml b/assets/csidriveroperators/azure-file/base/06_clusterrole.yaml index 30c65ba53..e6bb2d867 100644 --- a/assets/csidriveroperators/azure-file/base/06_clusterrole.yaml +++ b/assets/csidriveroperators/azure-file/base/06_clusterrole.yaml @@ -94,18 +94,6 @@ rules: - create - watch - delete -- apiGroups: - - coordination.k8s.io - resources: - - leases - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - apiGroups: - '' resources: @@ -306,8 +294,8 @@ rules: - watch # Allow kube-rbac-proxy to create TokenReview to be able to authenticate Prometheus when collecting metrics - apiGroups: - - "authentication.k8s.io" + - authentication.k8s.io resources: - - "tokenreviews" + - tokenreviews verbs: - - "create" + - create diff --git a/assets/csidriveroperators/azure-file/hypershift/guest/generated/rbac.authorization.k8s.io_v1_clusterrole_azure-file-csi-driver-operator-clusterrole.yaml b/assets/csidriveroperators/azure-file/hypershift/guest/generated/rbac.authorization.k8s.io_v1_clusterrole_azure-file-csi-driver-operator-clusterrole.yaml index 68110723c..1c98acf1a 100644 --- a/assets/csidriveroperators/azure-file/hypershift/guest/generated/rbac.authorization.k8s.io_v1_clusterrole_azure-file-csi-driver-operator-clusterrole.yaml +++ b/assets/csidriveroperators/azure-file/hypershift/guest/generated/rbac.authorization.k8s.io_v1_clusterrole_azure-file-csi-driver-operator-clusterrole.yaml @@ -93,18 +93,6 @@ rules: - create - watch - delete -- apiGroups: - - coordination.k8s.io - resources: - - leases - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - apiGroups: - "" resources: diff --git a/assets/csidriveroperators/azure-file/standalone/generated/rbac.authorization.k8s.io_v1_clusterrole_azure-file-csi-driver-operator-clusterrole.yaml b/assets/csidriveroperators/azure-file/standalone/generated/rbac.authorization.k8s.io_v1_clusterrole_azure-file-csi-driver-operator-clusterrole.yaml index 68110723c..1c98acf1a 100644 --- a/assets/csidriveroperators/azure-file/standalone/generated/rbac.authorization.k8s.io_v1_clusterrole_azure-file-csi-driver-operator-clusterrole.yaml +++ b/assets/csidriveroperators/azure-file/standalone/generated/rbac.authorization.k8s.io_v1_clusterrole_azure-file-csi-driver-operator-clusterrole.yaml @@ -93,18 +93,6 @@ rules: - create - watch - delete -- apiGroups: - - coordination.k8s.io - resources: - - leases - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - apiGroups: - "" resources: