Skip to content

Commit a916ac0

Browse files
authored
scope down CNINode RBAC (#279)
1 parent 97695bd commit a916ac0

File tree

2 files changed

+1
-3
lines changed

2 files changed

+1
-3
lines changed

config/rbac/role.yaml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -60,10 +60,8 @@ rules:
6060
- cninodes
6161
verbs:
6262
- create
63-
- delete
6463
- get
6564
- list
66-
- patch
6765
- watch
6866
- apiGroups:
6967
- vpcresources.k8s.aws

main.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -79,7 +79,7 @@ func init() {
7979
// +kubebuilder:rbac:groups=apps,resources=deployments,namespace=kube-system,resourceNames=vpc-resource-controller,verbs=get;list;watch
8080
// +kubebuilder:rbac:groups=crd.k8s.amazonaws.com,resources=eniconfigs,verbs=get;list;watch
8181
// +kubebuilder:rbac:groups=vpcresources.k8s.aws,resources=securitygrouppolicies,verbs=get;list;watch
82-
// +kubebuilder:rbac:groups=vpcresources.k8s.aws,resources=cninodes,verbs=get;list;watch;create;patch;delete
82+
// +kubebuilder:rbac:groups=vpcresources.k8s.aws,resources=cninodes,verbs=get;list;watch;create
8383

8484
// Migration to leases based leader election
8585
// +kubebuilder:rbac:groups=coordination.k8s.io,resources=leases,namespace=kube-system,verbs=create

0 commit comments

Comments
 (0)