Skip to content

Commit e1c01f8

Browse files
authored
Merge pull request #284 from davidz627/feature/updateRBAC
Update RBAC rules for external provisioner and attacher to the updated roles required based on upstream repositories
2 parents c86e922 + d1538d7 commit e1c01f8

File tree

2 files changed

+34
-27
lines changed

2 files changed

+34
-27
lines changed

deploy/kubernetes/base/setup-cluster.yaml

+9-6
Original file line numberDiff line numberDiff line change
@@ -54,12 +54,15 @@ rules:
5454
- apiGroups: ["storage.k8s.io"]
5555
resources: ["storageclasses"]
5656
verbs: ["get", "list", "watch"]
57+
- apiGroups: [""]
58+
resources: ["events"]
59+
verbs: ["list", "watch", "create", "update", "patch"]
5760
- apiGroups: ["storage.k8s.io"]
5861
resources: ["csinodes"]
5962
verbs: ["get", "list", "watch"]
6063
- apiGroups: [""]
61-
resources: ["events"]
62-
verbs: ["list", "watch", "create", "update", "patch"]
64+
resources: ["nodes"]
65+
verbs: ["get", "list", "watch"]
6366

6467
---
6568

@@ -85,16 +88,16 @@ metadata:
8588
rules:
8689
- apiGroups: [""]
8790
resources: ["persistentvolumes"]
88-
verbs: ["get", "list", "watch", "update"]
91+
verbs: ["get", "list", "watch", "update", "patch"]
8992
- apiGroups: [""]
9093
resources: ["nodes"]
9194
verbs: ["get", "list", "watch"]
92-
- apiGroups: ["csi.storage.k8s.io"]
93-
resources: ["csinodeinfos"]
95+
- apiGroups: ["storage.k8s.io"]
96+
resources: ["csinodes"]
9497
verbs: ["get", "list", "watch"]
9598
- apiGroups: ["storage.k8s.io"]
9699
resources: ["volumeattachments"]
97-
verbs: ["get", "list", "watch", "update"]
100+
verbs: ["get", "list", "watch", "update", "patch"]
98101

99102
---
100103

deploy/kubernetes/overlays/alpha/rbac_add_snapshotter.yaml

+25-21
Original file line numberDiff line numberDiff line change
@@ -4,27 +4,31 @@ kind: ClusterRole
44
metadata:
55
name: external-snapshotter-role
66
rules:
7-
- apiGroups: ["snapshot.storage.k8s.io"]
8-
resources: ["volumesnapshotclasses"]
9-
verbs: ["get", "list", "watch"]
10-
- apiGroups: ["snapshot.storage.k8s.io"]
11-
resources: ["volumesnapshotcontents"]
12-
verbs: ["create", "get", "list", "watch", "update", "delete"]
13-
- apiGroups: ["snapshot.storage.k8s.io"]
14-
resources: ["volumesnapshots"]
15-
verbs: ["get", "list", "watch", "update"]
16-
- apiGroups: ["apiextensions.k8s.io"]
17-
resources: ["customresourcedefinitions"]
18-
verbs: ["create", "list", "watch", "delete"]
19-
- apiGroups: [""]
20-
resources: ["events"]
21-
verbs: ["list", "watch", "create", "update", "patch"]
22-
- apiGroups: ["storage.k8s.io"]
23-
resources: ["storageclasses"]
24-
verbs: ["watch", "get", "list"]
25-
- apiGroups: ["admissionregistration.k8s.io"]
26-
resources: ["mutatingwebhookconfigurations"]
27-
verbs: ["create"]
7+
- apiGroups: [""]
8+
resources: ["persistentvolumes"]
9+
verbs: ["get", "list", "watch"]
10+
- apiGroups: [""]
11+
resources: ["persistentvolumeclaims"]
12+
verbs: ["get", "list", "watch", "update"]
13+
- apiGroups: ["storage.k8s.io"]
14+
resources: ["storageclasses"]
15+
verbs: ["get", "list", "watch"]
16+
- apiGroups: [""]
17+
resources: ["events"]
18+
verbs: ["list", "watch", "create", "update", "patch"]
19+
# Secrets resource ommitted since GCE PD snapshots does not require them
20+
- apiGroups: ["snapshot.storage.k8s.io"]
21+
resources: ["volumesnapshotclasses"]
22+
verbs: ["get", "list", "watch"]
23+
- apiGroups: ["snapshot.storage.k8s.io"]
24+
resources: ["volumesnapshotcontents"]
25+
verbs: ["create", "get", "list", "watch", "update", "delete"]
26+
- apiGroups: ["snapshot.storage.k8s.io"]
27+
resources: ["volumesnapshots"]
28+
verbs: ["get", "list", "watch", "update"]
29+
- apiGroups: ["apiextensions.k8s.io"]
30+
resources: ["customresourcedefinitions"]
31+
verbs: ["create", "list", "watch", "delete"]
2832

2933
---
3034

0 commit comments

Comments
 (0)