diff --git a/adguardhome/k8s/cert-sync-rbac.yaml b/adguardhome/k8s/cert-sync-rbac.yaml index 457cd75..084da9f 100644 --- a/adguardhome/k8s/cert-sync-rbac.yaml +++ b/adguardhome/k8s/cert-sync-rbac.yaml @@ -31,7 +31,14 @@ rules: - apiGroups: ["apps"] resources: ["deployments"] resourceNames: ["adguard-deployment"] - verbs: ["get", "list", "watch", "patch"] + verbs: ["get", "patch"] + # NOTE: list/watch cannot be combined with resourceNames (the API ignores + # the name filter for collection verbs, so the grant would be void). + # This rule is namespace-scoped to adguard, which holds a single + # Deployment; `rollout status` needs it to watch the rollout. + - apiGroups: ["apps"] + resources: ["deployments"] + verbs: ["list", "watch"] --- apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding