Skip to content

Commit 4edafa3

Browse files
committed
Remove RBAC grants when App & API Protection is not enabled
1 parent 59285d4 commit 4edafa3

39 files changed

+10
-1229
lines changed

charts/datadog/CHANGELOG.md

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,9 @@
11
# Datadog changelog
22

3+
## 3.162.1
4+
5+
* Remove RBAC grants when App & API Protection is not enabled.
6+
37
## 3.162.0
48

59
* Add injectionMode option for APM instrumentation ([#2308](https://github.com/DataDog/helm-charts/pull/2308)).
@@ -15,9 +19,9 @@
1519
## 3.161.0
1620

1721
* Update Datadog Operator dependency to 2.17.0 for image tag 1.22.0.
18-
22+
1923
Datadog Operator chart v2.17.0 [release notes](https://github.com/DataDog/helm-charts/releases/tag/datadog-operator-2.17.0).
20-
24+
2125
Datadog Operator v1.22.0 [release notes](https://github.com/DataDog/datadog-operator/releases/tag/v1.22.0).
2226

2327
## 3.160.4

charts/datadog/Chart.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
apiVersion: v1
33
name: datadog
4-
version: 3.162.0
4+
version: 3.162.1
55
appVersion: "7"
66
description: Datadog Agent
77
keywords:

charts/datadog/README.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
# Datadog
22

3-
![Version: 3.162.0](https://img.shields.io/badge/Version-3.162.0-informational?style=flat-square) ![AppVersion: 7](https://img.shields.io/badge/AppVersion-7-informational?style=flat-square)
3+
![Version: 3.162.1](https://img.shields.io/badge/Version-3.162.1-informational?style=flat-square) ![AppVersion: 7](https://img.shields.io/badge/AppVersion-7-informational?style=flat-square)
44

55
> [!WARNING]
66
> The Datadog Operator is now enabled by default since version [3.157.0](https://github.com/DataDog/helm-charts/blob/main/charts/datadog/CHANGELOG.md#31570) to collect chart metadata for display in [Fleet Automation](https://docs.datadoghq.com/agent/fleet_automation/). We are aware of issues affecting some environments and are actively working on fixes. We apologize for the inconvenience and appreciate your patience while we address these issues.

charts/datadog/templates/cluster-agent-rbac.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -392,6 +392,7 @@ rules:
392392
- get
393393
{{- include "orchestratorExplorer-config-crs" . }}
394394
{{- end }}
395+
{{- if .Values.datadog.appsec.injector.enabled }}
395396
# Used by datadog.appsec.injector feature
396397
- apiGroups:
397398
- "gateway.networking.k8s.io"
@@ -428,6 +429,7 @@ rules:
428429
- get
429430
- create
430431
- delete
432+
{{- end }}
431433
---
432434
apiVersion: {{ template "rbac.apiVersion" . }}
433435
kind: ClusterRoleBinding

test/datadog/baseline/manifests/adp_enabled.yaml

Lines changed: 0 additions & 35 deletions
Original file line numberDiff line numberDiff line change
@@ -884,41 +884,6 @@ rules:
884884
- list
885885
- watch
886886
- get
887-
- apiGroups:
888-
- gateway.networking.k8s.io
889-
resources:
890-
- gateways
891-
- gatewayclasses
892-
verbs:
893-
- get
894-
- list
895-
- watch
896-
- patch
897-
- apiGroups:
898-
- gateway.networking.k8s.io
899-
resources:
900-
- referencegrants
901-
verbs:
902-
- get
903-
- delete
904-
- create
905-
- patch
906-
- apiGroups:
907-
- gateway.envoyproxy.io
908-
resources:
909-
- envoyextensionpolicies
910-
verbs:
911-
- get
912-
- delete
913-
- create
914-
- apiGroups:
915-
- networking.istio.io
916-
resources:
917-
- envoyfilters
918-
verbs:
919-
- get
920-
- create
921-
- delete
922887
---
923888
apiVersion: rbac.authorization.k8s.io/v1
924889
kind: ClusterRole

test/datadog/baseline/manifests/agent-clusterchecks-deployment_default.yaml

Lines changed: 0 additions & 35 deletions
Original file line numberDiff line numberDiff line change
@@ -901,41 +901,6 @@ rules:
901901
- list
902902
- watch
903903
- get
904-
- apiGroups:
905-
- gateway.networking.k8s.io
906-
resources:
907-
- gateways
908-
- gatewayclasses
909-
verbs:
910-
- get
911-
- list
912-
- watch
913-
- patch
914-
- apiGroups:
915-
- gateway.networking.k8s.io
916-
resources:
917-
- referencegrants
918-
verbs:
919-
- get
920-
- delete
921-
- create
922-
- patch
923-
- apiGroups:
924-
- gateway.envoyproxy.io
925-
resources:
926-
- envoyextensionpolicies
927-
verbs:
928-
- get
929-
- delete
930-
- create
931-
- apiGroups:
932-
- networking.istio.io
933-
resources:
934-
- envoyfilters
935-
verbs:
936-
- get
937-
- create
938-
- delete
939904
---
940905
apiVersion: rbac.authorization.k8s.io/v1
941906
kind: ClusterRole

test/datadog/baseline/manifests/agent-workload_exclude.yaml

Lines changed: 0 additions & 35 deletions
Original file line numberDiff line numberDiff line change
@@ -884,41 +884,6 @@ rules:
884884
- list
885885
- watch
886886
- get
887-
- apiGroups:
888-
- gateway.networking.k8s.io
889-
resources:
890-
- gateways
891-
- gatewayclasses
892-
verbs:
893-
- get
894-
- list
895-
- watch
896-
- patch
897-
- apiGroups:
898-
- gateway.networking.k8s.io
899-
resources:
900-
- referencegrants
901-
verbs:
902-
- get
903-
- delete
904-
- create
905-
- patch
906-
- apiGroups:
907-
- gateway.envoyproxy.io
908-
resources:
909-
- envoyextensionpolicies
910-
verbs:
911-
- get
912-
- delete
913-
- create
914-
- apiGroups:
915-
- networking.istio.io
916-
resources:
917-
- envoyfilters
918-
verbs:
919-
- get
920-
- create
921-
- delete
922887
---
923888
apiVersion: rbac.authorization.k8s.io/v1
924889
kind: ClusterRole

test/datadog/baseline/manifests/cluster-agent-deployment_default.yaml

Lines changed: 0 additions & 35 deletions
Original file line numberDiff line numberDiff line change
@@ -897,41 +897,6 @@ rules:
897897
- list
898898
- watch
899899
- get
900-
- apiGroups:
901-
- gateway.networking.k8s.io
902-
resources:
903-
- gateways
904-
- gatewayclasses
905-
verbs:
906-
- get
907-
- list
908-
- watch
909-
- patch
910-
- apiGroups:
911-
- gateway.networking.k8s.io
912-
resources:
913-
- referencegrants
914-
verbs:
915-
- get
916-
- delete
917-
- create
918-
- patch
919-
- apiGroups:
920-
- gateway.envoyproxy.io
921-
resources:
922-
- envoyextensionpolicies
923-
verbs:
924-
- get
925-
- delete
926-
- create
927-
- apiGroups:
928-
- networking.istio.io
929-
resources:
930-
- envoyfilters
931-
verbs:
932-
- get
933-
- create
934-
- delete
935900
---
936901
apiVersion: rbac.authorization.k8s.io/v1
937902
kind: ClusterRole

test/datadog/baseline/manifests/cluster-agent-deployment_default_advanced_AC_injection.yaml

Lines changed: 0 additions & 35 deletions
Original file line numberDiff line numberDiff line change
@@ -897,41 +897,6 @@ rules:
897897
- list
898898
- watch
899899
- get
900-
- apiGroups:
901-
- gateway.networking.k8s.io
902-
resources:
903-
- gateways
904-
- gatewayclasses
905-
verbs:
906-
- get
907-
- list
908-
- watch
909-
- patch
910-
- apiGroups:
911-
- gateway.networking.k8s.io
912-
resources:
913-
- referencegrants
914-
verbs:
915-
- get
916-
- delete
917-
- create
918-
- patch
919-
- apiGroups:
920-
- gateway.envoyproxy.io
921-
resources:
922-
- envoyextensionpolicies
923-
verbs:
924-
- get
925-
- delete
926-
- create
927-
- apiGroups:
928-
- networking.istio.io
929-
resources:
930-
- envoyfilters
931-
verbs:
932-
- get
933-
- create
934-
- delete
935900
---
936901
apiVersion: rbac.authorization.k8s.io/v1
937902
kind: ClusterRole

test/datadog/baseline/manifests/cluster-agent-deployment_default_minimal_AC_injection.yaml

Lines changed: 0 additions & 35 deletions
Original file line numberDiff line numberDiff line change
@@ -897,41 +897,6 @@ rules:
897897
- list
898898
- watch
899899
- get
900-
- apiGroups:
901-
- gateway.networking.k8s.io
902-
resources:
903-
- gateways
904-
- gatewayclasses
905-
verbs:
906-
- get
907-
- list
908-
- watch
909-
- patch
910-
- apiGroups:
911-
- gateway.networking.k8s.io
912-
resources:
913-
- referencegrants
914-
verbs:
915-
- get
916-
- delete
917-
- create
918-
- patch
919-
- apiGroups:
920-
- gateway.envoyproxy.io
921-
resources:
922-
- envoyextensionpolicies
923-
verbs:
924-
- get
925-
- delete
926-
- create
927-
- apiGroups:
928-
- networking.istio.io
929-
resources:
930-
- envoyfilters
931-
verbs:
932-
- get
933-
- create
934-
- delete
935900
---
936901
apiVersion: rbac.authorization.k8s.io/v1
937902
kind: ClusterRole

0 commit comments

Comments
 (0)