Skip to content

Commit e8fddaf

Browse files
committed
Add tokenrequest RBAC for operator controller manager
1 parent 6cfc5d7 commit e8fddaf

File tree

3 files changed

+13
-0
lines changed

3 files changed

+13
-0
lines changed

bundle/manifests/cert-manager-operator.clusterserviceversion.yaml

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -332,6 +332,12 @@ spec:
332332
- patch
333333
- update
334334
- watch
335+
- apiGroups:
336+
- ""
337+
resources:
338+
- serviceaccounts/token
339+
verbs:
340+
- create
335341
- apiGroups:
336342
- acme.cert-manager.io
337343
resources:

config/rbac/role.yaml

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,12 @@ rules:
2222
- patch
2323
- update
2424
- watch
25+
- apiGroups:
26+
- ""
27+
resources:
28+
- serviceaccounts/token
29+
verbs:
30+
- create
2531
- apiGroups:
2632
- acme.cert-manager.io
2733
resources:

pkg/controller/deployment/certmanager_controller.go

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -43,6 +43,7 @@ type CertManagerReconciler struct {
4343
// TODO clusterpermissions carried over as is, need to be reduced
4444
//+kubebuilder:rbac:groups="",resources=pods;secrets,verbs=get;list;watch;create;update;patch;delete
4545
//+kubebuilder:rbac:groups="",resources=events;services;namespaces;serviceaccounts;configmaps,verbs=get;list;watch;create;update;patch;delete
46+
//+kubebuilder:rbac:groups="",resources=serviceaccounts/token,verbs=create
4647
//+kubebuilder:rbac:groups="rbac.authorization.k8s.io",resources=roles;rolebindings;clusterroles;clusterrolebindings,verbs=get;list;watch;create;update;patch;delete
4748
//+kubebuilder:rbac:groups="apiextensions.k8s.io",resources=customresourcedefinitions,verbs=get;list;watch;create;update;patch;delete
4849
//+kubebuilder:rbac:groups="admissionregistration.k8s.io",resources=mutatingwebhookconfigurations;validatingwebhookconfigurations,verbs=get;list;watch;create;update;patch;delete

0 commit comments

Comments
 (0)