Skip to content

Commit ba02637

Browse files
authored
Merge pull request #41 from IBM/fix-roles
add required roles
2 parents 1ae37e4 + dd4d6a9 commit ba02637

File tree

3 files changed

+9
-5
lines changed

3 files changed

+9
-5
lines changed

.secrets.baseline

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"files": "go.sum|^.secrets.baseline$",
44
"lines": null
55
},
6-
"generated_at": "2024-06-27T06:33:16Z",
6+
"generated_at": "2024-07-04T13:24:14Z",
77
"plugins_used": [
88
{
99
"name": "AWSKeyDetector"

controllers/constants/constants.go

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -27,6 +27,7 @@ const (
2727
NodesResource = "nodes"
2828
PersistentVolumesResource = "persistentvolumes"
2929
PersistentVolumeClaimsResource = "persistentvolumeclaims"
30+
ConfigMapResource = "configmaps"
3031

3132
VerbGet = "get"
3233
VerbList = "list"

controllers/internal/crutils/static_resource_generator.go

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -185,10 +185,13 @@ func (c *IBMObjectCSI) GenerateSCCForNodeClusterRole() *rbacv1.ClusterRole {
185185
},
186186
{
187187
APIGroups: []string{""},
188-
Resources: []string{
189-
constants.PersistentVolumesResource,
190-
constants.SecretsResource},
191-
Verbs: []string{constants.VerbGet},
188+
Resources: []string{constants.PersistentVolumesResource, constants.SecretsResource},
189+
Verbs: []string{constants.VerbGet},
190+
},
191+
{
192+
APIGroups: []string{""},
193+
Resources: []string{constants.ConfigMapResource},
194+
Verbs: []string{constants.VerbGet, constants.VerbList},
192195
},
193196
},
194197
}

0 commit comments

Comments
 (0)