Skip to content

Commit 0a9ac86

Browse files
committed
rbac: replace wildcard with a clear list of allowed verbs (#6233)
Signed-off-by: zhangzujian <zhangzujian.7@gmail.com>
1 parent ede6f5c commit 0a9ac86

File tree

3 files changed

+36
-6
lines changed

3 files changed

+36
-6
lines changed

charts/kube-ovn-v2/templates/rbac/ovn-CR.yaml

Lines changed: 12 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -51,7 +51,13 @@ rules:
5151
- qos-policies
5252
- qos-policies/status
5353
verbs:
54-
- "*"
54+
- create
55+
- get
56+
- list
57+
- update
58+
- patch
59+
- watch
60+
- delete
5561
- apiGroups:
5662
- ""
5763
resources:
@@ -166,7 +172,11 @@ rules:
166172
resources:
167173
- leases
168174
verbs:
169-
- "*"
175+
- create
176+
- update
177+
- patch
178+
- get
179+
- watch
170180
- apiGroups:
171181
- "kubevirt.io"
172182
resources:

charts/kube-ovn/templates/ovn-CR.yaml

Lines changed: 12 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -51,7 +51,13 @@ rules:
5151
- qos-policies
5252
- qos-policies/status
5353
verbs:
54-
- "*"
54+
- create
55+
- get
56+
- list
57+
- update
58+
- patch
59+
- watch
60+
- delete
5561
- apiGroups:
5662
- ""
5763
resources:
@@ -166,7 +172,11 @@ rules:
166172
resources:
167173
- leases
168174
verbs:
169-
- "*"
175+
- create
176+
- update
177+
- patch
178+
- get
179+
- watch
170180
- apiGroups:
171181
- "kubevirt.io"
172182
resources:

dist/images/install.sh

Lines changed: 12 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3918,7 +3918,13 @@ rules:
39183918
- qos-policies
39193919
- qos-policies/status
39203920
verbs:
3921-
- "*"
3921+
- create
3922+
- get
3923+
- list
3924+
- update
3925+
- patch
3926+
- watch
3927+
- delete
39223928
- apiGroups:
39233929
- ""
39243930
resources:
@@ -4033,7 +4039,11 @@ rules:
40334039
resources:
40344040
- leases
40354041
verbs:
4036-
- "*"
4042+
- create
4043+
- update
4044+
- patch
4045+
- get
4046+
- watch
40374047
- apiGroups:
40384048
- "kubevirt.io"
40394049
resources:

0 commit comments

Comments
 (0)