Merge "(fix) Update jarvis-system-el ClusterRole permissions"

This commit is contained in:
Zuul 2021-03-04 18:59:24 +00:00 committed by Gerrit Code Review
commit d9b3897fc6
2 changed files with 5 additions and 5 deletions

View File

@ -19,17 +19,17 @@ rules:
verbs: ["list", "get", "create", "delete"]
- apiGroups: [""]
resources: ["configmaps"]
verbs: ["get", "list", "watch", "create"]
verbs: ["get", "list", "watch", "create", "delete"]
# Permissions to create resources in associated TriggerTemplates
- apiGroups: ["tekton.dev"]
resources: ["pipelineruns", "pipelineresources", "taskruns", "pipelines","tasks"]
verbs: ["create", "get", "list", "delete"]
- apiGroups: [""]
resources: ["serviceaccounts"]
verbs: ["impersonate", "get", "create", "delete"]
verbs: ["impersonate", "get", "create", "delete", "list"]
- apiGroups: [""]
resources: ["secrets"]
verbs: ["get", "list", "create"]
verbs: ["get", "list", "create", "delete"]
- apiGroups: [""]
resources: ["services"]
verbs: ["get"]
@ -38,7 +38,7 @@ rules:
verbs: ["get"]
- apiGroups: ["rbac.authorization.k8s.io"]
resources: ["rolebindings"]
verbs: ["get", "create", "delete"]
verbs: ["get", "create", "delete", "list"]
...
{{- end -}}
{{- include "helpers.template.overlay" ( dict "Global" $ "template_definition" "ClusterRole-el" ) }}

View File

@ -31,7 +31,7 @@ spec:
else
echo "Namespace already exists, delete all resources for re-run."
kubectl delete pr -n jarvis-$(params.changeNumber)-$(params.patchSetNumber) --all
helm delete development-pipeline -n jarvis-$(params.changeNumber)-$(params.patchSetNumber) || true
helm delete development-pipeline -n jarvis-$(params.changeNumber)-$(params.patchSetNumber)
kubectl delete role -n jarvis-$(params.changeNumber)-$(params.patchSetNumber) --all
kubectl delete secret -n jarvis-$(params.changeNumber)-$(params.patchSetNumber) --all
kubectl delete sa -n jarvis-$(params.changeNumber)-$(params.patchSetNumber) --all