Skip to content

Commit c718ec8

Browse files
Merge pull request #812 from ecordell/admin-perms
feat(rbac): restrict permissions for namespace admins
2 parents 33ccf62 + 32965a5 commit c718ec8

File tree

2 files changed

+8
-2
lines changed

2 files changed

+8
-2
lines changed

deploy/chart/templates/0000_50_olm_09-aggregated.clusterrole.yaml

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,8 +8,11 @@ metadata:
88
rbac.authorization.k8s.io/aggregate-to-edit: "true"
99
rules:
1010
- apiGroups: ["operators.coreos.com"]
11-
resources: ["clusterserviceversions", "catalogsources", "installplans", "subscriptions", "packagemanifests"]
11+
resources: ["subscriptions"]
1212
verbs: ["create", "update", "patch", "delete"]
13+
- apiGroups: ["operators.coreos.com"]
14+
resources: ["clusterserviceversions", "catalogsources", "installplans", "subscriptions"]
15+
verbs: ["delete"]
1316
---
1417
kind: ClusterRole
1518
apiVersion: rbac.authorization.k8s.io/v1

manifests/0000_50_olm_09-aggregated.clusterrole.yaml

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,8 +8,11 @@ metadata:
88
rbac.authorization.k8s.io/aggregate-to-edit: "true"
99
rules:
1010
- apiGroups: ["operators.coreos.com"]
11-
resources: ["clusterserviceversions", "catalogsources", "installplans", "subscriptions", "packagemanifests"]
11+
resources: ["subscriptions"]
1212
verbs: ["create", "update", "patch", "delete"]
13+
- apiGroups: ["operators.coreos.com"]
14+
resources: ["clusterserviceversions", "catalogsources", "installplans", "subscriptions"]
15+
verbs: ["delete"]
1316
---
1417
kind: ClusterRole
1518
apiVersion: rbac.authorization.k8s.io/v1

0 commit comments

Comments
 (0)