fix(adguard): split deployment RBAC rule for list/watch
ci / lint-prettier (push) Successful in 3s
ci / lint-ruff (push) Successful in 5s
ci / lint-yaml (push) Successful in 2s
ci / lint-dockerfiles (push) Successful in 1s
ci / validate (push) Successful in 2s
ci / build (push) Skipped
ci / deploy-userbot-panel (push) Skipped
ci / lint-prettier (push) Successful in 3s
ci / lint-ruff (push) Successful in 5s
ci / lint-yaml (push) Successful in 2s
ci / lint-dockerfiles (push) Successful in 1s
ci / validate (push) Successful in 2s
ci / build (push) Skipped
ci / deploy-userbot-panel (push) Skipped
Collection verbs cannot combine with resourceNames (grant would be void). Instance verbs stay name-scoped to adguard-deployment; list/watch is namespace-scoped (single Deployment in ns).
This commit is contained in:
1 parent
a8f7c79934
commit
93d768e988
1 file changed
+8
-1
@@ -31,7 +31,14 @@ rules:
|
|||||||
- apiGroups: ["apps"]
|
- apiGroups: ["apps"]
|
||||||
resources: ["deployments"]
|
resources: ["deployments"]
|
||||||
resourceNames: ["adguard-deployment"]
|
resourceNames: ["adguard-deployment"]
|
||||||
verbs: ["get", "list", "watch", "patch"]
|
verbs: ["get", "patch"]
|
||||||
|
# NOTE: list/watch cannot be combined with resourceNames (the API ignores
|
||||||
|
# the name filter for collection verbs, so the grant would be void).
|
||||||
|
# This rule is namespace-scoped to adguard, which holds a single
|
||||||
|
# Deployment; `rollout status` needs it to watch the rollout.
|
||||||
|
- apiGroups: ["apps"]
|
||||||
|
resources: ["deployments"]
|
||||||
|
verbs: ["list", "watch"]
|
||||||
---
|
---
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: RoleBinding
|
kind: RoleBinding
|
||||||
|
|||||||
Reference in new issue
Block a user