Skip to content

Commit 44cb690

Browse files
authored
Merge pull request #8 from PaloAltoNetworks/add_privileged_bind
Agent on OpenShift clusters needs privileged bind for the compliance …
2 parents fc497e3 + 6649832 commit 44cb690

File tree

3 files changed

+15
-11
lines changed

3 files changed

+15
-11
lines changed

charts/konnector/Chart.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@ apiVersion: v2
22
name: konnector
33
description: Deploys Palo Alto Networks' Cortex KSPM connector for advanced Kubernetes security posture management.
44
type: application
5-
version: 1.0.11
5+
version: 1.0.12
66
appVersion: "1.0.0"
77
maintainers:
88
- name: Palo Alto Networks - Cortex KSPM team

charts/konnector/templates/rbac.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -82,7 +82,7 @@ roleRef:
8282
apiVersion: rbac.authorization.k8s.io/v1
8383
kind: ClusterRoleBinding
8484
metadata:
85-
name: {{ $bindingName }}
85+
name: {{ $bindingName }}-binding
8686
labels:
8787
{{- include "common.labels" $ | nindent 4 }}
8888
subjects:

charts/konnector/values.yaml

Lines changed: 13 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -86,7 +86,7 @@ system:
8686
# Cluster Role Resources
8787
# ==========================
8888
clusterRoles:
89-
connector-manager-creator:
89+
konnector-manager-creator:
9090
rules:
9191
- apiGroups: [""]
9292
resources: ["configmaps", "services", "serviceaccounts"]
@@ -100,7 +100,7 @@ system:
100100
- apiGroups: ["rbac.authorization.k8s.io"]
101101
resources: ["clusterroles", "roles", "rolebindings", "clusterrolebindings"]
102102
verbs: ["create", "patch", "delete"]
103-
cluster-manager:
103+
konnector-cluster-manager:
104104
rules:
105105
- apiGroups: [""]
106106
resources: ["namespaces", "secrets", "configmaps"]
@@ -111,7 +111,7 @@ system:
111111
- apiGroups: ["admissionregistration.k8s.io"]
112112
resources: ["validatingwebhookconfigurations"]
113113
verbs: ["update", "list", "watch", "get", "create", "patch", "delete"]
114-
read-inventory:
114+
konnector-read-inventory:
115115
rules:
116116
- apiGroups: [""]
117117
resources: ["namespaces", "pods", "serviceaccounts", "endpoints", "services", "configmaps", "secrets", "nodes", "nodes/proxy"]
@@ -128,22 +128,22 @@ system:
128128
- apiGroups: ["networking.k8s.io"]
129129
resources: ["networkpolicies", "ingresses"]
130130
verbs: ["get", "list", "watch"]
131-
crd-manager:
131+
konnector-crd-manager:
132132
rules:
133133
- apiGroups: ["apiextensions.k8s.io"]
134134
resources: ["customresourcedefinitions"]
135135
verbs: ["create", "get", "patch", "delete"]
136-
node-vm-discovery:
136+
konnector-node-vm-discovery:
137137
rules:
138138
- apiGroups: [""]
139139
resources: ["nodes"]
140140
verbs: ["get", "list", "patch"]
141-
aro-openshift-permissions:
141+
konnector-aro-openshift-permissions:
142142
rules:
143143
- apiGroups: ["aro.openshift.io"]
144144
resources: ["clusters"]
145145
verbs: ["get", "list", "watch"]
146-
general-openshift-permissions:
146+
konnector-general-openshift-permissions:
147147
rules:
148148
- apiGroups: ["config.openshift.io"]
149149
resources: ["clusterversions", "apiservers", "authentications", "clusteroperators", "oauths", "infrastructures"]
@@ -160,7 +160,7 @@ system:
160160
- apiGroups: ["security.openshift.io"]
161161
resources: ["securitycontextconstraints"]
162162
verbs: ["get", "list", "watch"]
163-
otel:
163+
konnector-otel:
164164
rules:
165165
- apiGroups: [""]
166166
resources: ["nodes/stats"]
@@ -179,10 +179,14 @@ system:
179179
verbs: ["get", "list", "watch"]
180180

181181
extraClusterRoleBindings:
182-
openshift-anyuid-crole-binding:
182+
konnector-openshift-anyuid:
183183
roleRef:
184184
apiGroup: security.openshift.io/v1
185185
name: system:openshift:scc:anyuid
186+
konnector-openshift-privileged:
187+
roleRef:
188+
apiGroup: security.openshift.io/v1
189+
name: system:openshift:scc:privileged
186190

187191
# ==========================
188192
# Secrets Resources

0 commit comments

Comments
 (0)