Prechádzať zdrojové kódy

feat: add RBAC rules for user-facing ClusterRoles (#2286)

Signed-off-by: Matthew Hembree <matthew_hembree@yahoo.com>
Matthew Hembree 2 rokov pred
rodič
commit
6a2a050928

+ 28 - 0
deploy/charts/external-secrets/templates/rbac.yaml

@@ -138,6 +138,19 @@ rules:
       - "get"
       - "watch"
       - "list"
+  - apiGroups:
+    - "generators.external-secrets.io"
+    resources:
+    - "acraccesstokens"
+    - "ecrauthorizationtokens"
+    - "fakes"
+    - "gcraccesstokens"
+    - "passwords"
+    - "vaultdynamicsecrets"
+    verbs:
+      - "get"
+      - "watch"
+      - "list"
 ---
 apiVersion: rbac.authorization.k8s.io/v1
 {{- if and .Values.scopedNamespace .Values.scopedRBAC }}
@@ -168,6 +181,21 @@ rules:
       - "deletecollection"
       - "patch"
       - "update"
+  - apiGroups:
+    - "generators.external-secrets.io"
+    resources:
+    - "acraccesstokens"
+    - "ecrauthorizationtokens"
+    - "fakes"
+    - "gcraccesstokens"
+    - "passwords"
+    - "vaultdynamicsecrets"
+    verbs:
+      - "create"
+      - "delete"
+      - "deletecollection"
+      - "patch"
+      - "update"
 ---
 apiVersion: rbac.authorization.k8s.io/v1
 {{- if and .Values.scopedNamespace .Values.scopedRBAC }}