Skip to content

Commit 8b2d4c5

Browse files
dprinceclaude
andcommitted
Remove proxy-rolebindings from all operator RBAC configurations
Removes the ClusterRoleBinding resources for proxy roles across all OpenStack operators in the bindata RBAC templates. This cleanup removes unnecessary proxy role bindings that are no longer needed. Jira: OSPRH-19169 Co-Authored-By: Claude <noreply@anthropic.com>
1 parent 35723e2 commit 8b2d4c5

24 files changed

Lines changed: 32 additions & 299 deletions

bindata/rbac/barbican-operator-rbac.yaml

Lines changed: 0 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -402,19 +402,6 @@ subjects:
402402
name: barbican-operator-controller-manager
403403
namespace: '{{ .OperatorNamespace }}'
404404
---
405-
apiVersion: rbac.authorization.k8s.io/v1
406-
kind: ClusterRoleBinding
407-
metadata:
408-
name: barbican-operator-proxy-rolebinding
409-
roleRef:
410-
apiGroup: rbac.authorization.k8s.io
411-
kind: ClusterRole
412-
name: barbican-operator-proxy-role
413-
subjects:
414-
- kind: ServiceAccount
415-
name: barbican-operator-controller-manager
416-
namespace: '{{ .OperatorNamespace }}'
417-
---
418405
apiVersion: v1
419406
kind: Service
420407
metadata:

bindata/rbac/cinder-operator-rbac.yaml

Lines changed: 0 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -446,19 +446,6 @@ subjects:
446446
name: cinder-operator-controller-manager
447447
namespace: '{{ .OperatorNamespace }}'
448448
---
449-
apiVersion: rbac.authorization.k8s.io/v1
450-
kind: ClusterRoleBinding
451-
metadata:
452-
name: cinder-operator-proxy-rolebinding
453-
roleRef:
454-
apiGroup: rbac.authorization.k8s.io
455-
kind: ClusterRole
456-
name: cinder-operator-proxy-role
457-
subjects:
458-
- kind: ServiceAccount
459-
name: cinder-operator-controller-manager
460-
namespace: '{{ .OperatorNamespace }}'
461-
---
462449
apiVersion: v1
463450
kind: Service
464451
metadata:

bindata/rbac/designate-operator-rbac.yaml

Lines changed: 0 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -555,19 +555,6 @@ subjects:
555555
name: designate-operator-controller-manager
556556
namespace: '{{ .OperatorNamespace }}'
557557
---
558-
apiVersion: rbac.authorization.k8s.io/v1
559-
kind: ClusterRoleBinding
560-
metadata:
561-
name: designate-operator-proxy-rolebinding
562-
roleRef:
563-
apiGroup: rbac.authorization.k8s.io
564-
kind: ClusterRole
565-
name: designate-operator-proxy-role
566-
subjects:
567-
- kind: ServiceAccount
568-
name: designate-operator-controller-manager
569-
namespace: '{{ .OperatorNamespace }}'
570-
---
571558
apiVersion: v1
572559
kind: Service
573560
metadata:

bindata/rbac/glance-operator-rbac.yaml

Lines changed: 0 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -393,19 +393,6 @@ subjects:
393393
name: glance-operator-controller-manager
394394
namespace: '{{ .OperatorNamespace }}'
395395
---
396-
apiVersion: rbac.authorization.k8s.io/v1
397-
kind: ClusterRoleBinding
398-
metadata:
399-
name: glance-operator-proxy-rolebinding
400-
roleRef:
401-
apiGroup: rbac.authorization.k8s.io
402-
kind: ClusterRole
403-
name: glance-operator-proxy-role
404-
subjects:
405-
- kind: ServiceAccount
406-
name: glance-operator-controller-manager
407-
namespace: '{{ .OperatorNamespace }}'
408-
---
409396
apiVersion: v1
410397
kind: Service
411398
metadata:

bindata/rbac/heat-operator-rbac.yaml

Lines changed: 0 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -403,19 +403,6 @@ subjects:
403403
name: heat-operator-controller-manager
404404
namespace: '{{ .OperatorNamespace }}'
405405
---
406-
apiVersion: rbac.authorization.k8s.io/v1
407-
kind: ClusterRoleBinding
408-
metadata:
409-
name: heat-operator-proxy-rolebinding
410-
roleRef:
411-
apiGroup: rbac.authorization.k8s.io
412-
kind: ClusterRole
413-
name: heat-operator-proxy-role
414-
subjects:
415-
- kind: ServiceAccount
416-
name: heat-operator-controller-manager
417-
namespace: '{{ .OperatorNamespace }}'
418-
---
419406
apiVersion: v1
420407
kind: Service
421408
metadata:

bindata/rbac/horizon-operator-rbac.yaml

Lines changed: 0 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -275,19 +275,6 @@ subjects:
275275
name: horizon-operator-controller-manager
276276
namespace: '{{ .OperatorNamespace }}'
277277
---
278-
apiVersion: rbac.authorization.k8s.io/v1
279-
kind: ClusterRoleBinding
280-
metadata:
281-
name: horizon-operator-proxy-rolebinding
282-
roleRef:
283-
apiGroup: rbac.authorization.k8s.io
284-
kind: ClusterRole
285-
name: horizon-operator-proxy-role
286-
subjects:
287-
- kind: ServiceAccount
288-
name: horizon-operator-controller-manager
289-
namespace: '{{ .OperatorNamespace }}'
290-
---
291278
apiVersion: v1
292279
kind: Service
293280
metadata:

bindata/rbac/infra-operator-rbac.yaml

Lines changed: 0 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -576,19 +576,6 @@ subjects:
576576
name: infra-operator-controller-manager
577577
namespace: '{{ .OperatorNamespace }}'
578578
---
579-
apiVersion: rbac.authorization.k8s.io/v1
580-
kind: ClusterRoleBinding
581-
metadata:
582-
name: infra-operator-proxy-rolebinding
583-
roleRef:
584-
apiGroup: rbac.authorization.k8s.io
585-
kind: ClusterRole
586-
name: infra-operator-proxy-role
587-
subjects:
588-
- kind: ServiceAccount
589-
name: infra-operator-controller-manager
590-
namespace: '{{ .OperatorNamespace }}'
591-
---
592579
apiVersion: v1
593580
kind: Service
594581
metadata:

bindata/rbac/ironic-operator-rbac.yaml

Lines changed: 0 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -481,19 +481,6 @@ subjects:
481481
name: ironic-operator-controller-manager
482482
namespace: '{{ .OperatorNamespace }}'
483483
---
484-
apiVersion: rbac.authorization.k8s.io/v1
485-
kind: ClusterRoleBinding
486-
metadata:
487-
name: ironic-operator-proxy-rolebinding
488-
roleRef:
489-
apiGroup: rbac.authorization.k8s.io
490-
kind: ClusterRole
491-
name: ironic-operator-proxy-role
492-
subjects:
493-
- kind: ServiceAccount
494-
name: ironic-operator-controller-manager
495-
namespace: '{{ .OperatorNamespace }}'
496-
---
497484
apiVersion: v1
498485
kind: Service
499486
metadata:

bindata/rbac/keystone-operator-rbac.yaml

Lines changed: 0 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -385,19 +385,6 @@ subjects:
385385
name: keystone-operator-controller-manager
386386
namespace: '{{ .OperatorNamespace }}'
387387
---
388-
apiVersion: rbac.authorization.k8s.io/v1
389-
kind: ClusterRoleBinding
390-
metadata:
391-
name: keystone-operator-proxy-rolebinding
392-
roleRef:
393-
apiGroup: rbac.authorization.k8s.io
394-
kind: ClusterRole
395-
name: keystone-operator-proxy-role
396-
subjects:
397-
- kind: ServiceAccount
398-
name: keystone-operator-controller-manager
399-
namespace: '{{ .OperatorNamespace }}'
400-
---
401388
apiVersion: v1
402389
kind: Service
403390
metadata:

bindata/rbac/manila-operator-rbac.yaml

Lines changed: 0 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -438,19 +438,6 @@ subjects:
438438
name: manila-operator-controller-manager
439439
namespace: '{{ .OperatorNamespace }}'
440440
---
441-
apiVersion: rbac.authorization.k8s.io/v1
442-
kind: ClusterRoleBinding
443-
metadata:
444-
name: manila-operator-proxy-rolebinding
445-
roleRef:
446-
apiGroup: rbac.authorization.k8s.io
447-
kind: ClusterRole
448-
name: manila-operator-proxy-role
449-
subjects:
450-
- kind: ServiceAccount
451-
name: manila-operator-controller-manager
452-
namespace: '{{ .OperatorNamespace }}'
453-
---
454441
apiVersion: v1
455442
kind: Service
456443
metadata:

0 commit comments

Comments
 (0)