Skip to content

Commit 227e94c

Browse files
committed
update vap to bypass fleet agents on arc clusters
1 parent 64e407a commit 227e94c

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

pkg/webhook/managedresource/validatingadmissionpolicy.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -67,7 +67,7 @@ func GetValidatingAdmissionPolicy(isHub bool) *admv1.ValidatingAdmissionPolicy {
6767
},
6868
Validations: []admv1.Validation{
6969
{
70-
Expression: `"system:masters" in request.userInfo.groups || "system:serviceaccounts:kube-system" in request.userInfo.groups`,
70+
Expression: `"system:masters" in request.userInfo.groups || "system:serviceaccounts:kube-system" in request.userInfo.groups || "system:serviceaccounts:fleet-system" in request.userInfo.groups`,
7171
Message: "Create, Update, or Delete operations on ARM managed resources is forbidden",
7272
Reason: &forbidden,
7373
},

0 commit comments

Comments
 (0)