Skip to content

Commit b3c1db6

Browse files
committed
add missing RBAC for dra resources
Signed-off-by: Varun Ramachandra Sekar <vsekar@nvidia.com>
1 parent fc92202 commit b3c1db6

File tree

3 files changed

+19
-0
lines changed

3 files changed

+19
-0
lines changed

config/rbac/role.yaml

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -212,6 +212,15 @@ rules:
212212
- patch
213213
- update
214214
- watch
215+
- apiGroups:
216+
- resource.k8s.io
217+
resources:
218+
- resourceclaims
219+
- resourceclaimtemplates
220+
verbs:
221+
- get
222+
- list
223+
- watch
215224
- apiGroups:
216225
- route.openshift.io
217226
resources:

deployments/helm/k8s-nim-operator/templates/manager-rbac.yaml

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -350,6 +350,15 @@ rules:
350350
- patch
351351
- update
352352
- watch
353+
- apiGroups:
354+
- resource.k8s.io
355+
resources:
356+
- resourceclaims
357+
- resourceclaimtemplates
358+
verbs:
359+
- get
360+
- list
361+
- watch
353362
- apiGroups:
354363
- route.openshift.io
355364
resources:

internal/controller/nimservice_controller.go

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -92,6 +92,7 @@ func NewNIMServiceReconciler(client client.Client, scheme *runtime.Scheme, updat
9292
// +kubebuilder:rbac:groups=security.openshift.io,resources=securitycontextconstraints,verbs=get;list;watch;create;update;patch;delete
9393
// +kubebuilder:rbac:groups=security.openshift.io,resources=securitycontextconstraints,verbs=use,resourceNames=nonroot
9494
// +kubebuilder:rbac:groups=rbac.authorization.k8s.io,resources=roles;rolebindings,verbs=get;list;watch;create;update;patch;delete
95+
// +kubebuilder:rbac:groups=resource.k8s.io,resources=resourceclaims;resourceclaimtemplates,verbs=get;list;watch
9596
// +kubebuilder:rbac:groups="",resources=serviceaccounts;pods;pods/eviction;services;services/finalizers;endpoints,verbs=get;list;watch;create;update;patch;delete
9697
// +kubebuilder:rbac:groups="",resources=persistentvolumeclaims;configmaps;secrets,verbs=get;list;watch;create;update;patch;delete
9798
// +kubebuilder:rbac:groups=apps,resources=deployments;statefulsets,verbs=get;list;watch;create;update;patch;delete

0 commit comments

Comments
 (0)