Skip to content

Commit 3248ba0

Browse files
Merge pull request #971 from flavianmissi/update-azure-creds-request
OCPBUGS-24649: add private endpoint permissions to Azure credentials request
2 parents 8f6d7cd + 3d050ab commit 3248ba0

File tree

1 file changed

+17
-0
lines changed

1 file changed

+17
-0
lines changed

manifests/01-registry-credentials-request-azure.yaml

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,23 @@ spec:
3030
- Microsoft.Storage/storageAccounts/delete
3131
- Microsoft.Storage/storageAccounts/listKeys/action
3232
- Microsoft.Resources/tags/write
33+
# the permissions below are only necessary when users request
34+
# the operator to configure a private storage account.
35+
- Microsoft.Network/privateEndpoints/write
36+
- Microsoft.Network/privateEndpoints/read
37+
- Microsoft.Network/privateEndpoints/privateDnsZoneGroups/write
38+
- Microsoft.Network/privateEndpoints/privateDnsZoneGroups/read
39+
- Microsoft.Network/privateDnsZones/read
40+
- Microsoft.Network/privateDnsZones/write
41+
- Microsoft.Network/privateDnsZones/join/action
42+
- Microsoft.Network/privateDnsZones/A/write
43+
- Microsoft.Network/privateDnsZones/virtualNetworkLinks/write
44+
- Microsoft.Network/privateDnsZones/virtualNetworkLinks/read
45+
- Microsoft.Network/networkInterfaces/read
46+
- Microsoft.Storage/storageAccounts/PrivateEndpointConnectionsApproval/action
47+
- Microsoft.Network/virtualNetworks/subnets/read
48+
- Microsoft.Network/virtualNetworks/subnets/join/action
49+
- Microsoft.Network/virtualNetworks/join/action
3350
dataPermissions:
3451
- Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete
3552
- Microsoft.Storage/storageAccounts/blobServices/containers/blobs/write

0 commit comments

Comments
 (0)