Skip to content

Commit 0bffcac

Browse files
authored
Add rbac for calico kube-controllers to access services (#12828)
1 parent c857252 commit 0bffcac

File tree

1 file changed

+10
-0
lines changed

1 file changed

+10
-0
lines changed

roles/kubernetes-apps/policy_controller/calico/templates/calico-kube-cr.yml.j2

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,16 @@ rules:
2626
verbs:
2727
- watch
2828
- list
29+
# Services are monitored for service LoadBalancer IP allocation
30+
- apiGroups: [""]
31+
resources:
32+
- services
33+
- services/status
34+
verbs:
35+
- get
36+
- list
37+
- update
38+
- watch
2939
{% elif calico_datastore == "kdd" %}
3040
# Nodes are watched to monitor for deletions.
3141
- apiGroups: [""]

0 commit comments

Comments
 (0)