Skip to content

Commit 72f12cd

Browse files
authored
Merge pull request #4 from PaloAltoNetworks/openshift-permissions
add openshift permissions for compliance scanning
2 parents f769634 + bddd23d commit 72f12cd

File tree

2 files changed

+15
-3
lines changed

2 files changed

+15
-3
lines changed

charts/konnector/Chart.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@ apiVersion: v2
22
name: konnector
33
description: Deploys Palo Alto Networks' Cortex KSPM connector for advanced Kubernetes security posture management.
44
type: application
5-
version: 1.0.7
5+
version: 1.0.8
66
appVersion: "1.0.0"
77
maintainers:
88
- name: Palo Alto Networks - Cortex KSPM team

charts/konnector/values.yaml

Lines changed: 14 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -135,14 +135,26 @@ system:
135135
- apiGroups: [""]
136136
resources: ["nodes"]
137137
verbs: ["get", "list", "patch"]
138-
openshift-cluster-info:
138+
openshift-permissions:
139139
rules:
140140
- apiGroups: ["config.openshift.io"]
141-
resources: ["clusterversions"]
141+
resources: ["clusterversions", "apiservers", "authentications", "clusteroperators", "oauths"]
142142
verbs: ["get", "list", "watch"]
143143
- apiGroups: ["aro.openshift.io"]
144144
resources: ["clusters"]
145145
verbs: ["get", "list", "watch"]
146+
- apiGroups: ["operator.openshift.io"]
147+
resources: ["kubeapiservers", "openshiftapiservers", "ingresscontrollers", "networks"]
148+
verbs: ["get", "list", "watch"]
149+
- apiGroups: ["image.openshift.io"]
150+
resources: ["images", "imagestreams"]
151+
verbs: ["get", "list", "watch"]
152+
- apiGroups: ["route.openshift.io"]
153+
resources: ["routes"]
154+
verbs: ["get", "list", "watch"]
155+
- apiGroups: ["security.openshift.io"]
156+
resources: ["securitycontextconstraints"]
157+
verbs: ["get", "list", "watch"]
146158
otel:
147159
rules:
148160
- apiGroups: [""]

0 commit comments

Comments
 (0)