Skip to content

Commit 4008733

Browse files
author
Martin Linkhorst
committed
fix permissions for kube-node-decommissioner
* pod list was missing * node update instead of patch
1 parent 5cb8c23 commit 4008733

File tree

1 file changed

+4
-1
lines changed

1 file changed

+4
-1
lines changed

cluster/manifests/kube-node-decommissioner/01-rbac.yaml

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -16,9 +16,12 @@ metadata:
1616
application: kubernetes
1717
component: kube-node-decommissioner
1818
rules:
19+
- apiGroups: [""]
20+
resources: ["pods"]
21+
verbs: ["list"]
1922
- apiGroups: [""]
2023
resources: ["nodes"]
21-
verbs: ["list", "patch"]
24+
verbs: ["list", "update"]
2225
---
2326
# This role binding allows service-account "kube-node-decommissioner" to
2427
# list and patch nodes.

0 commit comments

Comments
 (0)