@@ -7,16 +7,38 @@ metadata:
77 name : policy-addon-ctrl-manager-role
88rules :
99 - apiGroups :
10- - addon.open-cluster-management.io
10+ - " "
1111 resources :
12- - addondeploymentconfigs
12+ - events
13+ verbs :
14+ - create
15+ - get
16+ - list
17+ - patch
18+ - update
19+ - watch
20+ - apiGroups :
21+ - " "
22+ resources :
23+ - pods
24+ verbs :
25+ - get
26+ - list
27+ - watch
28+ - apiGroups :
29+ - " "
30+ resourceNames :
31+ - policy-encryption-key
32+ resources :
33+ - secrets
1334 verbs :
1435 - get
1536 - list
1637 - watch
1738 - apiGroups :
1839 - addon.open-cluster-management.io
1940 resources :
41+ - addondeploymentconfigs
2042 - clustermanagementaddons
2143 verbs :
2244 - get
@@ -27,17 +49,21 @@ rules:
2749 resourceNames :
2850 - config-policy-controller
2951 - governance-policy-framework
52+ - governance-standalone-hub-templating
3053 resources :
3154 - clustermanagementaddons/finalizers
55+ - managedclusteraddons/finalizers
3256 verbs :
3357 - update
3458 - apiGroups :
3559 - addon.open-cluster-management.io
3660 resourceNames :
3761 - config-policy-controller
3862 - governance-policy-framework
63+ - governance-standalone-hub-templating
3964 resources :
4065 - clustermanagementaddons/status
66+ - managedclusteraddons/status
4167 verbs :
4268 - patch
4369 - update
@@ -56,29 +82,11 @@ rules:
5682 resourceNames :
5783 - config-policy-controller
5884 - governance-policy-framework
85+ - governance-standalone-hub-templating
5986 resources :
6087 - managedclusteraddons
6188 verbs :
6289 - delete
63- - apiGroups :
64- - addon.open-cluster-management.io
65- resourceNames :
66- - config-policy-controller
67- - governance-policy-framework
68- resources :
69- - managedclusteraddons/finalizers
70- verbs :
71- - update
72- - apiGroups :
73- - addon.open-cluster-management.io
74- resourceNames :
75- - config-policy-controller
76- - governance-policy-framework
77- resources :
78- - managedclusteraddons/status
79- verbs :
80- - patch
81- - update
8290 - apiGroups :
8391 - authorization.k8s.io
8492 resources :
@@ -138,6 +146,7 @@ rules:
138146 resourceNames :
139147 - config-policy-controller
140148 - governance-policy-framework
149+ - governance-standalone-hub-templating
141150 resources :
142151 - leases
143152 verbs :
@@ -146,72 +155,6 @@ rules:
146155 - patch
147156 - update
148157 - watch
149- - apiGroups :
150- - " "
151- resources :
152- - events
153- verbs :
154- - create
155- - get
156- - list
157- - patch
158- - update
159- - watch
160- - apiGroups :
161- - " "
162- resources :
163- - pods
164- verbs :
165- - get
166- - list
167- - watch
168- - apiGroups :
169- - " "
170- resources :
171- - secrets
172- verbs :
173- - create
174- - apiGroups :
175- - " "
176- resourceNames :
177- - governance-policy-database
178- - policy-encryption-key
179- resources :
180- - secrets
181- verbs :
182- - get
183- - list
184- - watch
185- - apiGroups :
186- - " "
187- resourceNames :
188- - open-cluster-management-compliance-history-api-recorder
189- resources :
190- - secrets
191- verbs :
192- - delete
193- - get
194- - list
195- - patch
196- - update
197- - watch
198- - apiGroups :
199- - " "
200- resources :
201- - serviceaccounts
202- verbs :
203- - create
204- - apiGroups :
205- - " "
206- resourceNames :
207- - open-cluster-management-compliance-history-api-recorder
208- resources :
209- - serviceaccounts
210- verbs :
211- - delete
212- - get
213- - patch
214- - update
215158 - apiGroups :
216159 - policy.open-cluster-management.io
217160 resources :
@@ -238,20 +181,12 @@ rules:
238181 - get
239182 - patch
240183 - update
241- - apiGroups :
242- - rbac.authorization.k8s.io
243- resources :
244- - clusterroles
245- verbs :
246- - create
247184 - apiGroups :
248185 - rbac.authorization.k8s.io
249186 resourceNames :
250- - open-cluster-management:compliance-history-api-recorder
251- - open-cluster-management:config-policy-controller-hub
252- - open-cluster-management:policy-framework-hub
187+ - open-cluster-management:governance-standalone-hub-templating
253188 resources :
254- - clusterroles
189+ - clusterrolebindings
255190 verbs :
256191 - delete
257192 - get
@@ -260,40 +195,25 @@ rules:
260195 - apiGroups :
261196 - rbac.authorization.k8s.io
262197 resources :
198+ - clusterrolebindings
199+ - clusterroles
263200 - rolebindings
264201 verbs :
265202 - create
266203 - apiGroups :
267204 - rbac.authorization.k8s.io
268205 resourceNames :
269- - open-cluster-management:compliance-history-api-recorder
270206 - open-cluster-management:config-policy-controller-hub
207+ - open-cluster-management:governance-standalone-hub-templating
271208 - open-cluster-management:policy-framework-hub
272209 resources :
210+ - clusterroles
273211 - rolebindings
274212 verbs :
275213 - delete
276214 - get
277215 - patch
278216 - update
279- - apiGroups :
280- - route.openshift.io
281- resources :
282- - routes
283- verbs :
284- - create
285- - apiGroups :
286- - route.openshift.io
287- resourceNames :
288- - governance-history-api
289- resources :
290- - routes
291- verbs :
292- - delete
293- - get
294- - list
295- - update
296- - watch
297217 - apiGroups :
298218 - work.open-cluster-management.io
299219 resources :
0 commit comments