Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Add additional explicitly listed permission
Signed-off-by: Daniel Fan <[email protected]>
  • Loading branch information
Daniel-Fan committed Oct 16, 2023
commit a5a4245247f0977b7366d2c162bbe97451e8cf38
Original file line number Diff line number Diff line change
Expand Up @@ -594,9 +594,9 @@ spec:
app.kubernetes.io/instance: operand-deployment-lifecycle-manager
app.kubernetes.io/managed-by: operand-deployment-lifecycle-manager
app.kubernetes.io/name: operand-deployment-lifecycle-manager
productName: IBM_Cloud_Platform_Common_Services
intent: projected-odlm
name: operand-deployment-lifecycle-manager
productName: IBM_Cloud_Platform_Common_Services
spec:
affinity:
nodeAffinity:
Expand Down Expand Up @@ -680,9 +680,13 @@ spec:
- operator.ibm.com
resources:
- operandconfigs
- operandconfigs/status
- operandregistries
- operandregistries/status
- operandrequests
- operandrequests/status
- operandbindinfos
- operandbindinfos/status
verbs:
- create
- delete
Expand All @@ -697,6 +701,7 @@ spec:
- configmaps
- secrets
- services
- namespaces
verbs:
- create
- delete
Expand All @@ -717,6 +722,31 @@ spec:
- patch
- update
- watch
- apiGroups:
- operators.coreos.com
resources:
- operatorgroups
- installplans
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- k8s.keycloak.org
resources:
- keycloaks
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
serviceAccountName: operand-deployment-lifecycle-manager
strategy: deployment
installModes:
Expand Down
2 changes: 2 additions & 0 deletions config/manager/manager.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ metadata:
app.kubernetes.io/instance: "operand-deployment-lifecycle-manager"
app.kubernetes.io/managed-by: "operand-deployment-lifecycle-manager"
app.kubernetes.io/name: "operand-deployment-lifecycle-manager"
productName: IBM_Cloud_Platform_Common_Services
name: operand-deployment-lifecycle-manager
namespace: system
spec:
Expand All @@ -24,6 +25,7 @@ spec:
app.kubernetes.io/instance: operand-deployment-lifecycle-manager
app.kubernetes.io/managed-by: "operand-deployment-lifecycle-manager"
app.kubernetes.io/name: "operand-deployment-lifecycle-manager"
productName: IBM_Cloud_Platform_Common_Services
intent: projected-odlm
annotations:
productName: "IBM Cloud Platform Common Services"
Expand Down
30 changes: 30 additions & 0 deletions config/rbac/role.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -40,9 +40,13 @@ rules:
- operator.ibm.com
resources:
- operandconfigs
- operandconfigs/status
- operandregistries
- operandregistries/status
- operandrequests
- operandrequests/status
- operandbindinfos
- operandbindinfos/status
- verbs:
- create
- delete
Expand All @@ -57,6 +61,7 @@ rules:
- configmaps
- secrets
- services
- namespaces
- verbs:
- create
- delete
Expand All @@ -69,3 +74,28 @@ rules:
- route.openshift.io
resources:
- routes
- verbs:
- create
- delete
- get
- list
- patch
- update
- watch
apiGroups:
- operators.coreos.com
resources:
- operatorgroups
- installplans
- verbs:
- create
- delete
- get
- list
- patch
- update
- watch
apiGroups:
- k8s.keycloak.org
resources:
- keycloaks