Skip to content

Commit 3c87ec6

Browse files
authored
Merge pull request #9675 from zalando-incubator/kubernetes-resource-analyzer-secrets
Allow kubernetes-resource-analyzer to read secrets
2 parents 6ac81a5 + 9fb6e59 commit 3c87ec6

File tree

1 file changed

+33
-0
lines changed

1 file changed

+33
-0
lines changed

cluster/manifests/roles/kubernetes-resource-analyzer.yaml

Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,3 +13,36 @@ subjects:
1313
- apiGroup: rbac.authorization.k8s.io
1414
kind: User
1515
name: zalando-iam:zalando:service:stups_kubernetes
16+
---
17+
apiVersion: rbac.authorization.k8s.io/v1
18+
kind: ClusterRole
19+
metadata:
20+
name: kubernetes-resource-analyzer-secrets
21+
labels:
22+
application: kubernetes
23+
component: resource-analyzer
24+
rules:
25+
- apiGroups:
26+
- ""
27+
resources:
28+
- secrets
29+
verbs:
30+
- get
31+
- list
32+
- watch
33+
---
34+
apiVersion: rbac.authorization.k8s.io/v1
35+
kind: ClusterRoleBinding
36+
metadata:
37+
name: kubernetes-resource-analyzer-secrets
38+
labels:
39+
application: kubernetes
40+
component: resource-analyzer
41+
roleRef:
42+
apiGroup: rbac.authorization.k8s.io
43+
kind: ClusterRole
44+
name: kubernetes-resource-analyzer-secrets
45+
subjects:
46+
- apiGroup: rbac.authorization.k8s.io
47+
kind: User
48+
name: zalando-iam:zalando:service:stups_kubernetes

0 commit comments

Comments
 (0)