Skip to content

Commit 6f8c381

Browse files
committed
Add secrets read-only access to RBAC
1 parent 7abb7cc commit 6f8c381

File tree

2 files changed

+9
-0
lines changed

2 files changed

+9
-0
lines changed

config/rbac/role.yaml

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,14 @@ rules:
1313
verbs:
1414
- create
1515
- patch
16+
- apiGroups:
17+
- ""
18+
resources:
19+
- secrets
20+
verbs:
21+
- get
22+
- list
23+
- watch
1624
- apiGroups:
1725
- source.toolkit.fluxcd.io
1826
resources:

controllers/bucket_controller.go

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -56,6 +56,7 @@ type BucketReconciler struct {
5656

5757
// +kubebuilder:rbac:groups=source.toolkit.fluxcd.io,resources=buckets,verbs=get;list;watch;create;update;patch;delete
5858
// +kubebuilder:rbac:groups=source.toolkit.fluxcd.io,resources=buckets/status,verbs=get;update;patch
59+
// +kubebuilder:rbac:groups="",resources=secrets,verbs=get;list;watch
5960

6061
func (r *BucketReconciler) Reconcile(req ctrl.Request) (ctrl.Result, error) {
6162
ctx := context.Background()

0 commit comments

Comments
 (0)