|
| 1 | +apiVersion: rbac.authorization.k8s.io/v1 |
| 2 | +kind: ClusterRole |
| 3 | +metadata: |
| 4 | + name: {{ include "permission-manager.serviceAccountName" . }} |
| 5 | + labels: |
| 6 | + {{- include "permission-manager.labels" . | nindent 4 }} |
| 7 | +rules: |
| 8 | + # Allow full management of all the Permission Manager resources |
| 9 | + - apiGroups: [ "permissionmanager.user" ] |
| 10 | + resources: |
| 11 | + - "*" |
| 12 | + verbs: [ "get", "list", "create", "update", "delete", "watch" ] |
| 13 | + # Allow full management of the RBAC resources |
| 14 | + - apiGroups: |
| 15 | + - "rbac.authorization.k8s.io" |
| 16 | + resources: |
| 17 | + - "clusterrolebindings" |
| 18 | + - "clusterroles" |
| 19 | + - "rolebindings" |
| 20 | + - "roles" |
| 21 | + verbs: [ "get", "list", "create", "update", "delete", "bind", "watch" ] |
| 22 | + - apiGroups: [""] |
| 23 | + resources: |
| 24 | + - "serviceaccounts" |
| 25 | + - "secrets" |
| 26 | + verbs: [ "get", "list", "create", "update", "delete", "watch" ] |
| 27 | + # Allow full management of certificates CSR, including their approval |
| 28 | + - apiGroups: [ "certificates.k8s.io" ] |
| 29 | + resources: |
| 30 | + - "certificatesigningrequests" |
| 31 | + - "certificatesigningrequests/approval" |
| 32 | + verbs: [ "get", "list", "create", "update", "delete", "watch" ] |
| 33 | + # Support legacy versions, before signerName was added |
| 34 | + # (see https://github.com/kubernetes/kubernetes/pull/88246) |
| 35 | + - apiGroups: [ "certificates.k8s.io" ] |
| 36 | + resources: |
| 37 | + - "signers" |
| 38 | + resourceNames: |
| 39 | + - "kubernetes.io/legacy-unknown" |
| 40 | + - "kubernetes.io/kube-apiserver-client" |
| 41 | + verbs: [ "approve" ] |
| 42 | + # Allow to get and list Namespaces |
| 43 | + - apiGroups: [ "" ] |
| 44 | + resources: |
| 45 | + - "namespaces" |
| 46 | + verbs: [ "get", "list" ] |
| 47 | + |
0 commit comments