Preflight checklist
Ory Network Project
No response
Describe the bug
This is a regression since v0.0.40 (my guess would be that there's a problem with the last commit). No problem with v0.0.39.
When hydra-maester is used in "singleNamespaceMode" (parameter from values.yaml), it fails to start start with the following error message:
ERROR controller-runtime.cache.UnhandledError Failed to watch {"reflector": "pkg/mod/k8s.io/[email protected]/tools/cache/reflector.go:290", "type": "*v1alpha1.OAuth2Client", "error": "failed to list *v1alpha1.OAuth2Client: oauth2clients.hydra.ory.sh is forbidden: User \"system:serviceaccount:default:hydra-maester-account\" cannot list resource \"oauth2clients\" in API group \"hydra.ory.sh\" at the cluster scope"}
Hydra-maester shouldn't try to watch resources cluster wide in this mode.
Also, I checked: hydra-maester starts with arg "--namespace=default".
Reproducing the bug
With helm, set "singleNamespaceMode: true" and deploy.
Relevant log output
Relevant configuration
Version
v0.0.40
On which operating system are you observing this issue?
None
In which environment are you deploying?
Kubernetes
Additional Context
I templated the manifests with helm but use them with kustomize, though it shouldn't change anything.
Preflight checklist
Ory Network Project
No response
Describe the bug
This is a regression since v0.0.40 (my guess would be that there's a problem with the last commit). No problem with v0.0.39.
When hydra-maester is used in "singleNamespaceMode" (parameter from values.yaml), it fails to start start with the following error message:
Hydra-maester shouldn't try to watch resources cluster wide in this mode.
Also, I checked: hydra-maester starts with arg "--namespace=default".
Reproducing the bug
With helm, set "singleNamespaceMode: true" and deploy.
Relevant log output
Relevant configuration
Version
v0.0.40
On which operating system are you observing this issue?
None
In which environment are you deploying?
Kubernetes
Additional Context
I templated the manifests with helm but use them with kustomize, though it shouldn't change anything.