Skip to content

Commit 104eae9

Browse files
authored
fix: update vap to bypass fleet agents on arc clusters (#1188)
2 parents 64e407a + 227e94c commit 104eae9

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

pkg/webhook/managedresource/validatingadmissionpolicy.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -67,7 +67,7 @@ func GetValidatingAdmissionPolicy(isHub bool) *admv1.ValidatingAdmissionPolicy {
6767
},
6868
Validations: []admv1.Validation{
6969
{
70-
Expression: `"system:masters" in request.userInfo.groups || "system:serviceaccounts:kube-system" in request.userInfo.groups`,
70+
Expression: `"system:masters" in request.userInfo.groups || "system:serviceaccounts:kube-system" in request.userInfo.groups || "system:serviceaccounts:fleet-system" in request.userInfo.groups`,
7171
Message: "Create, Update, or Delete operations on ARM managed resources is forbidden",
7272
Reason: &forbidden,
7373
},

0 commit comments

Comments
 (0)