Skip to content

Commit 4e96bc4

Browse files
Merge pull request #890 from abutcher/IR-363
IR-363: Update Azure Credentials Request manifest of the Cluster Image Registry Operator to use new API field for requesting permissions
2 parents c3674a0 + 6ef401e commit 4e96bc4

File tree

1 file changed

+16
-3
lines changed

1 file changed

+16
-3
lines changed

manifests/01-registry-credentials-request-azure.yaml

Lines changed: 16 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,19 @@ spec:
1919
providerSpec:
2020
apiVersion: cloudcredential.openshift.io/v1
2121
kind: AzureProviderSpec
22-
roleBindings:
23-
- role: Storage Blob Data Contributor
24-
- role: Contributor
22+
permissions:
23+
- Microsoft.Storage/storageAccounts/blobServices/read
24+
- Microsoft.Storage/storageAccounts/blobServices/containers/read
25+
- Microsoft.Storage/storageAccounts/blobServices/containers/write
26+
- Microsoft.Storage/storageAccounts/blobServices/generateUserDelegationKey/action
27+
- Microsoft.Storage/storageAccounts/read
28+
- Microsoft.Storage/storageAccounts/write
29+
- Microsoft.Storage/storageAccounts/delete
30+
- Microsoft.Storage/storageAccounts/listKeys/action
31+
- Microsoft.Resources/tags/write
32+
dataPermissions:
33+
- Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete
34+
- Microsoft.Storage/storageAccounts/blobServices/containers/blobs/write
35+
- Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read
36+
- Microsoft.Storage/storageAccounts/blobServices/containers/blobs/add/action
37+
- Microsoft.Storage/storageAccounts/blobServices/containers/blobs/move/action

0 commit comments

Comments
 (0)