Skip to content

Commit 3065c09

Browse files
authored
Merge pull request #618 from sluetze/sandboxed-containers
add read permission for kataconfig
2 parents f072f9c + 485aeb9 commit 3065c09

File tree

3 files changed

+22
-0
lines changed

3 files changed

+22
-0
lines changed

bundle/manifests/compliance-operator.clusterserviceversion.yaml

+7
Original file line numberDiff line numberDiff line change
@@ -1098,6 +1098,13 @@ spec:
10981098
verbs:
10991099
- get
11001100
- list
1101+
- apiGroups:
1102+
- kataconfiguration.openshift.io
1103+
resources:
1104+
- kataconfigs
1105+
verbs:
1106+
- list
1107+
- get
11011108
serviceAccountName: api-resource-collector
11021109
- rules:
11031110
- apiGroups:

config/manifests/bases/compliance-operator.clusterserviceversion.yaml

+7
Original file line numberDiff line numberDiff line change
@@ -1176,6 +1176,13 @@ spec:
11761176
- get
11771177
- list
11781178
- watch
1179+
- apiGroups:
1180+
- kataconfiguration.openshift.io
1181+
resources:
1182+
- kataconfigs
1183+
verbs:
1184+
- list
1185+
- get
11791186
serviceAccountName: api-resource-collector
11801187
- rules:
11811188
- apiGroups:

config/rbac/api_resource_collector_cluster_role.yaml

+8
Original file line numberDiff line numberDiff line change
@@ -867,3 +867,11 @@ rules:
867867
verbs:
868868
- get
869869
- list
870+
# Necessary to check for sandboxed-containers config for BSI requirements
871+
- apiGroups:
872+
- kataconfiguration.openshift.io
873+
verbs:
874+
- list
875+
- get
876+
resources:
877+
- kataconfigs

0 commit comments

Comments
 (0)