Skip to content

Commit f94d6df

Browse files
authored
Merge pull request #8537 from zalando-incubator/drop-secret-read
[RBAC] drop secret read permission from poweruser ClusterRole
2 parents 0b3171b + 6bda2f6 commit f94d6df

File tree

2 files changed

+12
-0
lines changed

2 files changed

+12
-0
lines changed

cluster/manifests/roles/collaborator-roles.yaml

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,16 @@ rules:
1414
- update
1515
- patch
1616
- delete
17+
{{ if eq .Cluster.ConfigItems.role_sync_controller_enabled "true" }}
18+
- apiGroups:
19+
- ""
20+
resources:
21+
- secrets
22+
verbs:
23+
- get
24+
- list
25+
- watch
26+
{{ end }}
1727
---
1828
kind: RoleBinding
1929
apiVersion: rbac.authorization.k8s.io/v1

cluster/manifests/roles/poweruser-role.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -58,6 +58,7 @@ rules:
5858
- services/proxy
5959
verbs:
6060
- get
61+
{{ if ne .Cluster.ConfigItems.role_sync_controller_enabled "true" }}
6162
- apiGroups:
6263
- ''
6364
resources:
@@ -71,6 +72,7 @@ rules:
7172
- patch
7273
- update
7374
- watch
75+
{{ end }}
7476
- apiGroups:
7577
- ''
7678
- extensions

0 commit comments

Comments
 (0)