From 93d768e9887cd38d83b5fb2152cebf0eb872c607 Mon Sep 17 00:00:00 2001 From: mr-forust Date: Wed, 23 Sep 2026 13:54:06 +0200 Subject: [PATCH] fix(adguard): split deployment RBAC rule for list/watch Collection verbs cannot combine with resourceNames (grant would be void). Instance verbs stay name-scoped to adguard-deployment; list/watch is namespace-scoped (single Deployment in ns). --- adguardhome/k8s/cert-sync-rbac.yaml | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/adguardhome/k8s/cert-sync-rbac.yaml b/adguardhome/k8s/cert-sync-rbac.yaml index 457cd75..084da9f 100644 --- a/adguardhome/k8s/cert-sync-rbac.yaml +++ b/adguardhome/k8s/cert-sync-rbac.yaml @@ -31,7 +31,14 @@ rules: - apiGroups: ["apps"] resources: ["deployments"] resourceNames: ["adguard-deployment"] - verbs: ["get", "list", "watch", "patch"] + verbs: ["get", "patch"] + # NOTE: list/watch cannot be combined with resourceNames (the API ignores + # the name filter for collection verbs, so the grant would be void). + # This rule is namespace-scoped to adguard, which holds a single + # Deployment; `rollout status` needs it to watch the rollout. + - apiGroups: ["apps"] + resources: ["deployments"] + verbs: ["list", "watch"] --- apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding