Skip to content

Commit 3145cd4

Browse files
author
rrajashe
committed
Add Cluster role for kyverno
This will make sure kyverno has permission over the resources referenced in the policy
1 parent 338033f commit 3145cd4

File tree

2 files changed

+38
-0
lines changed

2 files changed

+38
-0
lines changed
+5
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
apiVersion: kustomize.config.k8s.io/v1beta1
2+
kind: Kustomization
3+
resources:
4+
- update_namespace_labels.yaml
5+
- kyverno_rbac.yaml
+33
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
---
2+
apiVersion: rbac.authorization.k8s.io/v1
3+
kind: ClusterRole
4+
metadata:
5+
name: kyverno-read-kubearchiveconfig
6+
labels:
7+
rbac.kyverno.io/aggregate-to-admission-controller: "true"
8+
rules:
9+
- apiGroups:
10+
- kubearchive.kubearchive.org
11+
resources:
12+
- kubearchiveconfigs
13+
verbs:
14+
- list
15+
- get
16+
---
17+
apiVersion: rbac.authorization.k8s.io/v1
18+
kind: ClusterRole
19+
metadata:
20+
name: kyverno-manage-kubearchiveconfig
21+
labels:
22+
rbac.kyverno.io/aggregate-to-background-controller: "true"
23+
rules:
24+
- apiGroups:
25+
- kubearchive.kubearchive.org
26+
resources:
27+
- kubearchiveconfigs
28+
verbs:
29+
- create
30+
- get
31+
- list
32+
- delete
33+
- update

0 commit comments

Comments
 (0)