Skip to content

Commit a30fefa

Browse files
authored
Add permissions to list and watch ConfigMaps and Secrets
Required since #379 Without that, the following error is triggered: ``` E k8s.io/kube-state-metrics/collectors/collectors.go:62: Failed to list *v1.ConfigMap: configmaps is forbidden: User "system:serviceaccount:monitoring:kube-state-metrics" cannot list configmaps at the cluster scope: Unknown user "system:serviceaccount:monitoring:kube-state-metrics" E k8s.io/kube-state-metrics/collectors/collectors.go:62: Failed to list *v1.Secret: secrets is forbidden: User "system:serviceaccount:monitoring:kube-state-metrics" cannot list secrets at the cluster scope: Unknown user "system:serviceaccount:monitoring:kube-state-metrics" E k8s.io/kube-state-metrics/collectors/collectors.go:62: Failed to list *v1.ConfigMap: configmaps is forbidden: User "system:serviceaccount:monitoring:kube-state-metrics" cannot list configmaps at the cluster scope: Unknown user "system:serviceaccount:monitoring:kube-state-metrics" ```
1 parent f882f0a commit a30fefa

1 file changed

Lines changed: 2 additions & 0 deletions

File tree

kubernetes/kube-state-metrics-cluster-role.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,8 @@ metadata:
66
rules:
77
- apiGroups: [""]
88
resources:
9+
- configmaps
10+
- secrets
911
- nodes
1012
- pods
1113
- services

0 commit comments

Comments
 (0)