Skip to content

Commit 6fbcd00

Browse files
author
yoobinshin
committed
allow-list ocp controller sa in vap
1 parent 2bf8667 commit 6fbcd00

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

pkg/webhook/managedresource/validatingadmissionpolicy.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -75,7 +75,7 @@ func mutateValidatingAdmissionPolicy(vap *admv1.ValidatingAdmissionPolicy, isHub
7575
},
7676
Validations: []admv1.Validation{
7777
{
78-
Expression: `"system:masters" in request.userInfo.groups || "system:serviceaccounts:kube-system" in request.userInfo.groups || "system:serviceaccounts:fleet-system" in request.userInfo.groups`,
78+
Expression: `"system:masters" in request.userInfo.groups || "system:serviceaccounts:kube-system" in request.userInfo.groups || "system:serviceaccounts:fleet-system" in request.userInfo.groups || "system:serviceaccounts:openshift-kube-controller-manager" in request.userInfo.groups`,
7979
Message: "Create, Update, or Delete operations on ARM managed resources is forbidden",
8080
Reason: &forbidden,
8181
},

0 commit comments

Comments
 (0)