Skip to content

Commit

Permalink
patch to staging cluster-provisioner pod read
Browse files Browse the repository at this point in the history
Signed-off-by: Adam Scerra <[email protected]>
  • Loading branch information
ascerra committed Nov 14, 2024
1 parent e42ca6f commit 4999c2a
Show file tree
Hide file tree
Showing 4 changed files with 30 additions and 0 deletions.
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: cluster-provisioner
rules:
- apiGroups: [""]
resources: ["pods/log"]
verbs: ["get"]
2 changes: 2 additions & 0 deletions components/cluster-as-a-service/staging/kustomization.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,8 @@ resources:
- ../base
- ../../openshift-gitops
- external-secrets.yaml
- namespace-manager-pod-reader-role.yaml
- namespace-manager-pod-reader-binding.yaml
patches:
- path: add-hypershift-params.yaml
target:
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: namespace-manager-pod-reader-binding
subjects:
- kind: ServiceAccount
name: namespace-manager
namespace: ${SPACE_NAME}-eaas
roleRef:
kind: ClusterRole
name: namespace-manager-pod-reader
apiGroup: rbac.authorization.k8s.io
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: namespace-manager-pod-reader
rules:
- apiGroups: [""]
resources: ["pods/log"]
verbs: ["get"]

0 comments on commit 4999c2a

Please sign in to comment.