Skip to content

Commit

Permalink
fix(rbac): update roles in plain manifests (#185)
Browse files Browse the repository at this point in the history
  • Loading branch information
corrieriluca authored Nov 6, 2023
1 parent 983ad07 commit 577adf5
Show file tree
Hide file tree
Showing 10 changed files with 149 additions and 51 deletions.
29 changes: 20 additions & 9 deletions manifests/base/controllers/clusterrole.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -7,14 +7,24 @@ metadata:
app.kubernetes.io/name: burrito-controllers
app.kubernetes.io/part-of: burrito
rules:
- apiGroups: ["events.k8s.io"]
resources: ["events"]
verbs: ["create", "update"]
- apiGroups: [""]
resources: ["events"]
verbs: ["create", "update"]
- apiGroups: [""]
resources: ["pods"]
- apiGroups:
- events.k8s.io
resources:
- events
verbs:
- create
- update
- apiGroups:
- ""
resources:
- events
verbs:
- create
- update
- apiGroups:
- ""
resources:
- pods
verbs:
- create
- delete
Expand All @@ -30,6 +40,7 @@ rules:
verbs:
- create
- delete
- deletecollection
- get
- list
- patch
Expand Down Expand Up @@ -128,7 +139,7 @@ rules:
- patch
- update
- apiGroups:
- "coordination.k8s.io"
- coordination.k8s.io
resources:
- leases
verbs:
Expand Down
29 changes: 29 additions & 0 deletions manifests/base/runner/clusterrole.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
labels:
app.kubernetes.io/component: runner
app.kubernetes.io/name: burrito-runner
app.kubernetes.io/part-of: burrito
name: burrito-runner
rules:
- apiGroups:
- coordination.k8s.io
resources:
- leases
verbs:
- get
- delete
- apiGroups:
- config.terraform.padok.cloud
resources:
- terraformlayers
verbs:
- get
- patch
- apiGroups:
- config.terraform.padok.cloud
resources:
- terraformrepositories
verbs:
- get
2 changes: 1 addition & 1 deletion manifests/base/runner/clusterrolebinding.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ metadata:
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: burrito-controllers
name: burrito-runner
subjects:
- kind: ServiceAccount
name: burrito-runner
Expand Down
1 change: 1 addition & 0 deletions manifests/base/runner/kustomization.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -3,4 +3,5 @@ kind: Kustomization

resources:
- serviceaccount.yaml
- clusterrole.yaml
- clusterrolebinding.yaml
41 changes: 29 additions & 12 deletions manifests/base/server/clusterrole.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,6 @@ rules:
- config.terraform.padok.cloud
resources:
- terraformlayers
- terraformpullrequests
verbs:
- create
- delete
Expand All @@ -23,21 +22,25 @@ rules:
- apiGroups:
- config.terraform.padok.cloud
resources:
- terraformlayers/finalizers
- terraformrepositories
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- config.terraform.padok.cloud
resources:
- terraformlayers/status
- terraformlayers/finalizers
verbs:
- get
- patch
- update
- apiGroups:
- config.terraform.padok.cloud
resources:
- terraformrepositories
- terraformpullrequests
verbs:
- create
- delete
Expand All @@ -49,26 +52,40 @@ rules:
- apiGroups:
- config.terraform.padok.cloud
resources:
- terraformrepositories/finalizers
- terraformpullrequests/finalizers
verbs:
- update
- apiGroups:
- config.terraform.padok.cloud
resources:
- terraformrepositories/status
- terraformpullrequests/status
verbs:
- get
- patch
- update
- apiGroups:
- "coordination.k8s.io"
- config.terraform.padok.cloud
resources:
- leases
- terraformruns
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- create
- apiGroups:
- config.terraform.padok.cloud
resources:
- terraformruns/finalizers
verbs:
- update
- apiGroups:
- config.terraform.padok.cloud
resources:
- terraformruns/status
verbs:
- get
- patch
- delete
- update
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,7 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.11.2
creationTimestamp: null
controller-gen.kubebuilder.io/version: v0.11.4
name: terraformlayers.config.terraform.padok.cloud
spec:
group: config.terraform.padok.cloud
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,7 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.11.2
creationTimestamp: null
controller-gen.kubebuilder.io/version: v0.11.4
name: terraformpullrequests.config.terraform.padok.cloud
spec:
group: config.terraform.padok.cloud
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,7 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.11.2
creationTimestamp: null
controller-gen.kubebuilder.io/version: v0.11.4
name: terraformrepositories.config.terraform.padok.cloud
spec:
group: config.terraform.padok.cloud
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,7 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.11.2
creationTimestamp: null
controller-gen.kubebuilder.io/version: v0.11.4
name: terraformruns.config.terraform.padok.cloud
spec:
group: config.terraform.padok.cloud
Expand Down
Loading

0 comments on commit 577adf5

Please sign in to comment.