@@ -86,7 +86,7 @@ system:
86
86
# Cluster Role Resources
87
87
# ==========================
88
88
clusterRoles :
89
- connector -manager-creator :
89
+ konnector -manager-creator :
90
90
rules :
91
91
- apiGroups : [""]
92
92
resources : ["configmaps", "services", "serviceaccounts"]
@@ -100,15 +100,18 @@ system:
100
100
- apiGroups : ["rbac.authorization.k8s.io"]
101
101
resources : ["clusterroles", "roles", "rolebindings", "clusterrolebindings"]
102
102
verbs : ["create", "patch", "delete"]
103
- cluster-manager :
103
+ konnector- cluster-manager :
104
104
rules :
105
- - apiGroups : ["", "coordination.k8s.io"]
106
- resources : ["leases", "namespaces", "secrets", "configmaps"]
105
+ - apiGroups : [""]
106
+ resources : ["namespaces", "secrets", "configmaps"]
107
+ verbs : ["get", "update", "patch", "list", "watch"]
108
+ - apiGroups : ["coordination.k8s.io"]
109
+ resources : ["leases"]
107
110
verbs : ["get", "update", "patch", "list", "watch"]
108
111
- apiGroups : ["admissionregistration.k8s.io"]
109
112
resources : ["validatingwebhookconfigurations"]
110
113
verbs : ["update", "list", "watch", "get", "create", "patch", "delete"]
111
- read-inventory :
114
+ konnector- read-inventory :
112
115
rules :
113
116
- apiGroups : [""]
114
117
resources : ["namespaces", "pods", "serviceaccounts", "endpoints", "services", "configmaps", "secrets", "nodes", "nodes/proxy"]
@@ -125,24 +128,26 @@ system:
125
128
- apiGroups : ["networking.k8s.io"]
126
129
resources : ["networkpolicies", "ingresses"]
127
130
verbs : ["get", "list", "watch"]
128
- crd-manager :
131
+ konnector- crd-manager :
129
132
rules :
130
133
- apiGroups : ["apiextensions.k8s.io"]
131
134
resources : ["customresourcedefinitions"]
132
135
verbs : ["create", "get", "patch", "delete"]
133
- node-vm-discovery :
136
+ konnector- node-vm-discovery :
134
137
rules :
135
138
- apiGroups : [""]
136
139
resources : ["nodes"]
137
140
verbs : ["get", "list", "patch"]
138
- openshift-permissions :
141
+ konnector-aro- openshift-permissions :
139
142
rules :
140
- - apiGroups : ["config.openshift.io"]
141
- resources : ["clusterversions", "apiservers", "authentications", "clusteroperators", "oauths", "infrastructures"]
142
- verbs : ["get", "list", "watch"]
143
143
- apiGroups : ["aro.openshift.io"]
144
144
resources : ["clusters"]
145
145
verbs : ["get", "list", "watch"]
146
+ konnector-general-openshift-permissions :
147
+ rules :
148
+ - apiGroups : ["config.openshift.io"]
149
+ resources : ["clusterversions", "apiservers", "authentications", "clusteroperators", "oauths", "infrastructures"]
150
+ verbs : ["get", "list", "watch"]
146
151
- apiGroups : ["operator.openshift.io"]
147
152
resources : ["kubeapiservers", "openshiftapiservers", "ingresscontrollers", "networks"]
148
153
verbs : ["get", "list", "watch"]
@@ -155,7 +160,7 @@ system:
155
160
- apiGroups : ["security.openshift.io"]
156
161
resources : ["securitycontextconstraints"]
157
162
verbs : ["get", "list", "watch"]
158
- otel :
163
+ konnector- otel :
159
164
rules :
160
165
- apiGroups : [""]
161
166
resources : ["nodes/stats"]
@@ -166,20 +171,31 @@ system:
166
171
- apiGroups : ["apps"]
167
172
resources : ["daemonsets", "deployments", "replicasets", "statefulsets"]
168
173
verbs : ["get", "list", "watch"]
169
- - apiGroups : ["extensions"]
170
- resources : ["daemonsets", "deployments", "replicasets"]
171
- verbs : ["get", "list", "watch"]
172
174
- apiGroups : ["batch"]
173
175
resources : ["jobs", "cronjobs"]
174
176
verbs : ["get", "list", "watch"]
175
177
- apiGroups : ["autoscaling"]
176
178
resources : ["horizontalpodautoscalers"]
177
179
verbs : ["get", "list", "watch"]
180
+ konnector-bc :
181
+ skipValidation : " true"
182
+ rules :
183
+ - apiGroups : ["extensions"]
184
+ resources : ["daemonsets", "deployments", "replicasets"]
185
+ verbs : ["get", "list", "watch"]
186
+ - apiGroups : ["", "coordination.k8s.io"]
187
+ resources : ["leases", "namespaces", "secrets", "configmaps"]
188
+ verbs : ["get", "update", "patch", "list", "watch"]
178
189
179
190
extraClusterRoleBindings :
180
- openshift-anyuid-crole-binding :
191
+ konnector- openshift-anyuid :
181
192
roleRef :
193
+ apiGroup : security.openshift.io/v1
182
194
name : system:openshift:scc:anyuid
195
+ konnector-openshift-privileged :
196
+ roleRef :
197
+ apiGroup : security.openshift.io/v1
198
+ name : system:openshift:scc:privileged
183
199
184
200
# ==========================
185
201
# Secrets Resources
0 commit comments