Fix sipcluster-infra-service ClusterRole

SIP needs permission to create, modify, and watch deployments. While
deployments is listed in one of the SIP ClusterRoles, the apiGroup apps
is not present, so SIP cannot watch deplyoments that manage
infrastructure services. This change adds the missing apiGroup.

Signed-off-by: Drew Walters <andrew.walters@att.com>
Change-Id: Ie376649cd67a82501c72d3ffdbb67cfe6e802934
This commit is contained in:
Drew Walters 2021-02-24 20:10:45 +00:00
parent 4ac8ec174e
commit 324e4e5ed3
5 changed files with 8 additions and 7 deletions

View File

@ -9,4 +9,4 @@ roleRef:
subjects:
- kind: ServiceAccount
name: default
namespace: sip-cluster-system
namespace: sipcluster-system

View File

@ -9,4 +9,4 @@ roleRef:
subjects:
- kind: ServiceAccount
name: default
namespace: sip-cluster-system
namespace: sipcluster-system

View File

@ -9,4 +9,4 @@ roleRef:
subjects:
- kind: ServiceAccount
name: default
namespace: sip-cluster-system
namespace: sipcluster-system

View File

@ -10,7 +10,7 @@ roleRef:
subjects:
- kind: ServiceAccount
name: default
namespace: sip-cluster-system
namespace: sipcluster-system
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
@ -23,7 +23,7 @@ roleRef:
subjects:
- kind: ServiceAccount
name: default
namespace: sip-cluster-system
namespace: sipcluster-system
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
@ -36,4 +36,4 @@ roleRef:
subjects:
- kind: ServiceAccount
name: default
namespace: sip-cluster-system
namespace: sipcluster-system

View File

@ -50,7 +50,6 @@ rules:
- ""
resources:
- namespaces
- deployments
- secrets
verbs:
- create
@ -67,8 +66,10 @@ metadata:
rules:
- apiGroups:
- ""
- apps
resources:
- configmaps
- deployments
- services
verbs:
- create