@@ -7,16 +7,38 @@ metadata:
7
7
name : policy-addon-ctrl-manager-role
8
8
rules :
9
9
- apiGroups :
10
- - addon.open-cluster-management.io
10
+ - " "
11
11
resources :
12
- - addondeploymentconfigs
12
+ - events
13
+ verbs :
14
+ - create
15
+ - get
16
+ - list
17
+ - patch
18
+ - update
19
+ - watch
20
+ - apiGroups :
21
+ - " "
22
+ resources :
23
+ - pods
24
+ verbs :
25
+ - get
26
+ - list
27
+ - watch
28
+ - apiGroups :
29
+ - " "
30
+ resourceNames :
31
+ - policy-encryption-key
32
+ resources :
33
+ - secrets
13
34
verbs :
14
35
- get
15
36
- list
16
37
- watch
17
38
- apiGroups :
18
39
- addon.open-cluster-management.io
19
40
resources :
41
+ - addondeploymentconfigs
20
42
- clustermanagementaddons
21
43
verbs :
22
44
- get
@@ -27,17 +49,21 @@ rules:
27
49
resourceNames :
28
50
- config-policy-controller
29
51
- governance-policy-framework
52
+ - governance-standalone-hub-templating
30
53
resources :
31
54
- clustermanagementaddons/finalizers
55
+ - managedclusteraddons/finalizers
32
56
verbs :
33
57
- update
34
58
- apiGroups :
35
59
- addon.open-cluster-management.io
36
60
resourceNames :
37
61
- config-policy-controller
38
62
- governance-policy-framework
63
+ - governance-standalone-hub-templating
39
64
resources :
40
65
- clustermanagementaddons/status
66
+ - managedclusteraddons/status
41
67
verbs :
42
68
- patch
43
69
- update
@@ -56,29 +82,11 @@ rules:
56
82
resourceNames :
57
83
- config-policy-controller
58
84
- governance-policy-framework
85
+ - governance-standalone-hub-templating
59
86
resources :
60
87
- managedclusteraddons
61
88
verbs :
62
89
- delete
63
- - apiGroups :
64
- - addon.open-cluster-management.io
65
- resourceNames :
66
- - config-policy-controller
67
- - governance-policy-framework
68
- resources :
69
- - managedclusteraddons/finalizers
70
- verbs :
71
- - update
72
- - apiGroups :
73
- - addon.open-cluster-management.io
74
- resourceNames :
75
- - config-policy-controller
76
- - governance-policy-framework
77
- resources :
78
- - managedclusteraddons/status
79
- verbs :
80
- - patch
81
- - update
82
90
- apiGroups :
83
91
- authorization.k8s.io
84
92
resources :
@@ -138,6 +146,7 @@ rules:
138
146
resourceNames :
139
147
- config-policy-controller
140
148
- governance-policy-framework
149
+ - governance-standalone-hub-templating
141
150
resources :
142
151
- leases
143
152
verbs :
@@ -146,72 +155,6 @@ rules:
146
155
- patch
147
156
- update
148
157
- watch
149
- - apiGroups :
150
- - " "
151
- resources :
152
- - events
153
- verbs :
154
- - create
155
- - get
156
- - list
157
- - patch
158
- - update
159
- - watch
160
- - apiGroups :
161
- - " "
162
- resources :
163
- - pods
164
- verbs :
165
- - get
166
- - list
167
- - watch
168
- - apiGroups :
169
- - " "
170
- resources :
171
- - secrets
172
- verbs :
173
- - create
174
- - apiGroups :
175
- - " "
176
- resourceNames :
177
- - governance-policy-database
178
- - policy-encryption-key
179
- resources :
180
- - secrets
181
- verbs :
182
- - get
183
- - list
184
- - watch
185
- - apiGroups :
186
- - " "
187
- resourceNames :
188
- - open-cluster-management-compliance-history-api-recorder
189
- resources :
190
- - secrets
191
- verbs :
192
- - delete
193
- - get
194
- - list
195
- - patch
196
- - update
197
- - watch
198
- - apiGroups :
199
- - " "
200
- resources :
201
- - serviceaccounts
202
- verbs :
203
- - create
204
- - apiGroups :
205
- - " "
206
- resourceNames :
207
- - open-cluster-management-compliance-history-api-recorder
208
- resources :
209
- - serviceaccounts
210
- verbs :
211
- - delete
212
- - get
213
- - patch
214
- - update
215
158
- apiGroups :
216
159
- policy.open-cluster-management.io
217
160
resources :
@@ -238,20 +181,12 @@ rules:
238
181
- get
239
182
- patch
240
183
- update
241
- - apiGroups :
242
- - rbac.authorization.k8s.io
243
- resources :
244
- - clusterroles
245
- verbs :
246
- - create
247
184
- apiGroups :
248
185
- rbac.authorization.k8s.io
249
186
resourceNames :
250
- - open-cluster-management:compliance-history-api-recorder
251
- - open-cluster-management:config-policy-controller-hub
252
- - open-cluster-management:policy-framework-hub
187
+ - open-cluster-management:governance-standalone-hub-templating
253
188
resources :
254
- - clusterroles
189
+ - clusterrolebindings
255
190
verbs :
256
191
- delete
257
192
- get
@@ -260,40 +195,25 @@ rules:
260
195
- apiGroups :
261
196
- rbac.authorization.k8s.io
262
197
resources :
198
+ - clusterrolebindings
199
+ - clusterroles
263
200
- rolebindings
264
201
verbs :
265
202
- create
266
203
- apiGroups :
267
204
- rbac.authorization.k8s.io
268
205
resourceNames :
269
- - open-cluster-management:compliance-history-api-recorder
270
206
- open-cluster-management:config-policy-controller-hub
207
+ - open-cluster-management:governance-standalone-hub-templating
271
208
- open-cluster-management:policy-framework-hub
272
209
resources :
210
+ - clusterroles
273
211
- rolebindings
274
212
verbs :
275
213
- delete
276
214
- get
277
215
- patch
278
216
- update
279
- - apiGroups :
280
- - route.openshift.io
281
- resources :
282
- - routes
283
- verbs :
284
- - create
285
- - apiGroups :
286
- - route.openshift.io
287
- resourceNames :
288
- - governance-history-api
289
- resources :
290
- - routes
291
- verbs :
292
- - delete
293
- - get
294
- - list
295
- - update
296
- - watch
297
217
- apiGroups :
298
218
- work.open-cluster-management.io
299
219
resources :
0 commit comments