Skip to content

Commit 74b4324

Browse files
fix: add missing resource names to ESO policy rules (#55)
1 parent c314e3a commit 74b4324

File tree

1 file changed

+34
-4
lines changed

1 file changed

+34
-4
lines changed

pkg/controlplane/components/eso_component.go

Lines changed: 34 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -39,17 +39,32 @@ func (e *ExternalSecretsOperator) GetPolicyRules() PolicyRules {
3939
{
4040
APIGroups: []string{"external-secrets.io"},
4141
Resources: []string{
42-
"externalsecrets",
43-
"secretstores",
42+
"clusterexternalsecrets",
43+
"clusterpushsecrets",
4444
"clustersecretstores",
45+
"externalsecrets",
4546
"pushsecrets",
47+
"secretstores",
4648
},
4749
Verbs: VerbsAdmin,
4850
},
4951
{
5052
APIGroups: []string{"generators.external-secrets.io"},
5153
Resources: []string{
54+
"acraccesstokens",
55+
"clustergenerators",
56+
"ecrauthorizationtokens",
57+
"fakes",
58+
"gcraccesstokens",
59+
"generatorstates",
60+
"githubaccesstokens",
61+
"grafanas",
62+
"passwords",
63+
"quayaccesstokens",
64+
"stssessiontokens",
65+
"uuids",
5266
"vaultdynamicsecrets",
67+
"webhooks",
5368
},
5469
Verbs: VerbsAdmin,
5570
},
@@ -58,17 +73,32 @@ func (e *ExternalSecretsOperator) GetPolicyRules() PolicyRules {
5873
{
5974
APIGroups: []string{"external-secrets.io"},
6075
Resources: []string{
61-
"externalsecrets",
62-
"secretstores",
76+
"clusterexternalsecrets",
77+
"clusterpushsecrets",
6378
"clustersecretstores",
79+
"externalsecrets",
6480
"pushsecrets",
81+
"secretstores",
6582
},
6683
Verbs: VerbsView,
6784
},
6885
{
6986
APIGroups: []string{"generators.external-secrets.io"},
7087
Resources: []string{
88+
"acraccesstokens",
89+
"clustergenerators",
90+
"ecrauthorizationtokens",
91+
"fakes",
92+
"gcraccesstokens",
93+
"generatorstates",
94+
"githubaccesstokens",
95+
"grafanas",
96+
"passwords",
97+
"quayaccesstokens",
98+
"stssessiontokens",
99+
"uuids",
71100
"vaultdynamicsecrets",
101+
"webhooks",
72102
},
73103
Verbs: VerbsView,
74104
},

0 commit comments

Comments
 (0)