fix(adguard): split deployment RBAC rule for list/watch
ci / lint-prettier (push) Successful in 3s
ci / lint-ruff (push) Successful in 5s
ci / lint-yaml (push) Successful in 2s
ci / lint-dockerfiles (push) Successful in 1s
ci / validate (push) Successful in 2s
ci / build (push) Skipped
ci / deploy-userbot-panel (push) Skipped

Collection verbs cannot combine with resourceNames (grant would
be void). Instance verbs stay name-scoped to adguard-deployment;
list/watch is namespace-scoped (single Deployment in ns).
This commit is contained in:
forust committed 2026-09-23 13:54:06 +02:00
1 parent a8f7c79934
commit 93d768e988
1 file changed
+8 -1
+8 -1
View File
@@ -31,7 +31,14 @@ rules:
- apiGroups: ["apps"]
resources: ["deployments"]
resourceNames: ["adguard-deployment"]
verbs: ["get", "list", "watch", "patch"]
verbs: ["get", "patch"]
# NOTE: list/watch cannot be combined with resourceNames (the API ignores
# the name filter for collection verbs, so the grant would be void).
# This rule is namespace-scoped to adguard, which holds a single
# Deployment; `rollout status` needs it to watch the rollout.
- apiGroups: ["apps"]
resources: ["deployments"]
verbs: ["list", "watch"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding