Merge pull request #2701 from fluxcd/add-sa-read

Grant service account read-only access to controllers
This commit is contained in:
Stefan Prodan 2022-05-04 11:33:15 +03:00 committed by GitHub
commit 45876a723c
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -23,6 +23,8 @@ rules:
resources:
- namespaces
- secrets
- configmaps
- serviceaccounts
verbs:
- get
- list
@ -34,19 +36,27 @@ rules:
verbs:
- create
- patch
# required by leader election
- apiGroups:
- ""
- ""
resources:
- configmaps
- configmaps/status
- configmaps
verbs:
- get
- list
- watch
- create
- update
- patch
- delete
- get
- list
- watch
- create
- update
- patch
- delete
- apiGroups:
- ""
resources:
- configmaps/status
verbs:
- get
- update
- patch
- apiGroups:
- "coordination.k8s.io"
resources: