Skip to content

Commit 232a896

Browse files
committed
01-cluster-admin
1 parent 734cbe2 commit 232a896

File tree

6 files changed

+27
-384
lines changed

6 files changed

+27
-384
lines changed
Lines changed: 5 additions & 98 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
{{- if and .Values.options.operatorController.enabled (not (has "BoxcutterRuntime" .Values.operatorConrollerFeatures)) }}
1+
{{- if .Values.options.operatorController.enabled }}
22
apiVersion: rbac.authorization.k8s.io/v1
33
kind: ClusterRole
44
metadata:
@@ -9,107 +9,14 @@ metadata:
99
annotations:
1010
{{- include "olmv1.annotations" . | nindent 4 }}
1111
rules:
12-
- apiGroups:
13-
- ""
14-
resources:
15-
- serviceaccounts/token
16-
verbs:
17-
- create
18-
- apiGroups:
19-
- ""
20-
resources:
21-
- serviceaccounts
22-
verbs:
23-
- get
24-
- apiGroups:
25-
- apiextensions.k8s.io
26-
resources:
27-
- customresourcedefinitions
28-
verbs:
29-
- get
30-
- apiGroups:
31-
- olm.operatorframework.io
32-
resources:
33-
- clustercatalogs
34-
verbs:
35-
- get
36-
- list
37-
- watch
38-
- apiGroups:
39-
- olm.operatorframework.io
40-
resources:
41-
- clusterextensions
42-
verbs:
43-
- get
44-
- list
45-
- patch
46-
- update
47-
- watch
48-
- apiGroups:
49-
- olm.operatorframework.io
50-
resources:
51-
- clusterextensions/finalizers
52-
verbs:
53-
- update
54-
- apiGroups:
55-
- olm.operatorframework.io
56-
resources:
57-
- clusterextensions/status
58-
verbs:
59-
- patch
60-
- update
61-
- apiGroups:
62-
- rbac.authorization.k8s.io
63-
resources:
64-
- clusterrolebindings
65-
- clusterroles
66-
- rolebindings
67-
- roles
68-
verbs:
69-
- list
70-
- watch
71-
{{- if .Values.options.openshift.enabled }}
72-
- apiGroups:
73-
- security.openshift.io
74-
resources:
75-
- securitycontextconstraints
76-
resourceNames:
77-
- privileged
78-
verbs:
79-
- use
80-
{{- end }}
81-
{{- if has "BoxcutterRuntime" .Values.options.operatorController.features.enabled }}
8212
- apiGroups:
8313
- "*"
8414
resources:
8515
- "*"
8616
verbs:
87-
- list
88-
- watch
89-
- apiGroups:
90-
- olm.operatorframework.io
91-
resources:
92-
- clusterextensionrevisions
93-
verbs:
94-
- create
95-
- delete
96-
- get
97-
- list
98-
- patch
99-
- update
100-
- watch
101-
- apiGroups:
102-
- olm.operatorframework.io
103-
resources:
104-
- clusterextensionrevisions/status
105-
verbs:
106-
- patch
107-
- update
108-
- apiGroups:
109-
- olm.operatorframework.io
110-
resources:
111-
- clusterextensionrevisions/finalizers
17+
- "*"
18+
- nonResourceURLs:
19+
- "*"
11220
verbs:
113-
- update
114-
{{- end }}
21+
- "*"
11522
{{- end }}

helm/olmv1/templates/rbac/clusterrolebinding-operator-controller-manager-rolebinding.yml

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -8,11 +8,7 @@ metadata:
88
labels:
99
app.kubernetes.io/name: operator-controller
1010
{{- include "olmv1.labels" $ | nindent 4 }}
11-
{{- if has "BoxcutterRuntime" .Values.options.operatorController.features.enabled }}
12-
name: operator-controller-manager-admin-rolebinding
13-
{{- else }}
1411
name: operator-controller-manager-rolebinding
15-
{{- end }}
1612
roleRef:
1713
apiGroup: rbac.authorization.k8s.io
1814
kind: ClusterRole

manifests/experimental-e2e.yaml

Lines changed: 5 additions & 86 deletions
Original file line numberDiff line numberDiff line change
@@ -1805,97 +1805,16 @@ metadata:
18051805
annotations:
18061806
olm.operatorframework.io/feature-set: experimental-e2e
18071807
rules:
1808-
- apiGroups:
1809-
- ""
1810-
resources:
1811-
- serviceaccounts/token
1812-
verbs:
1813-
- create
1814-
- apiGroups:
1815-
- ""
1816-
resources:
1817-
- serviceaccounts
1818-
verbs:
1819-
- get
1820-
- apiGroups:
1821-
- apiextensions.k8s.io
1822-
resources:
1823-
- customresourcedefinitions
1824-
verbs:
1825-
- get
1826-
- apiGroups:
1827-
- olm.operatorframework.io
1828-
resources:
1829-
- clustercatalogs
1830-
verbs:
1831-
- get
1832-
- list
1833-
- watch
1834-
- apiGroups:
1835-
- olm.operatorframework.io
1836-
resources:
1837-
- clusterextensions
1838-
verbs:
1839-
- get
1840-
- list
1841-
- patch
1842-
- update
1843-
- watch
1844-
- apiGroups:
1845-
- olm.operatorframework.io
1846-
resources:
1847-
- clusterextensions/finalizers
1848-
verbs:
1849-
- update
1850-
- apiGroups:
1851-
- olm.operatorframework.io
1852-
resources:
1853-
- clusterextensions/status
1854-
verbs:
1855-
- patch
1856-
- update
1857-
- apiGroups:
1858-
- rbac.authorization.k8s.io
1859-
resources:
1860-
- clusterrolebindings
1861-
- clusterroles
1862-
- rolebindings
1863-
- roles
1864-
verbs:
1865-
- list
1866-
- watch
18671808
- apiGroups:
18681809
- "*"
18691810
resources:
18701811
- "*"
18711812
verbs:
1872-
- list
1873-
- watch
1874-
- apiGroups:
1875-
- olm.operatorframework.io
1876-
resources:
1877-
- clusterextensionrevisions
1878-
verbs:
1879-
- create
1880-
- delete
1881-
- get
1882-
- list
1883-
- patch
1884-
- update
1885-
- watch
1886-
- apiGroups:
1887-
- olm.operatorframework.io
1888-
resources:
1889-
- clusterextensionrevisions/status
1890-
verbs:
1891-
- patch
1892-
- update
1893-
- apiGroups:
1894-
- olm.operatorframework.io
1895-
resources:
1896-
- clusterextensionrevisions/finalizers
1813+
- "*"
1814+
- nonResourceURLs:
1815+
- "*"
18971816
verbs:
1898-
- update
1817+
- "*"
18991818
---
19001819
# Source: olmv1/templates/rbac/clusterrolebinding-catalogd-manager-rolebinding.yml
19011820
apiVersion: rbac.authorization.k8s.io/v1
@@ -1963,7 +1882,7 @@ metadata:
19631882
labels:
19641883
app.kubernetes.io/name: operator-controller
19651884
app.kubernetes.io/part-of: olm
1966-
name: operator-controller-manager-admin-rolebinding
1885+
name: operator-controller-manager-rolebinding
19671886
roleRef:
19681887
apiGroup: rbac.authorization.k8s.io
19691888
kind: ClusterRole

manifests/experimental.yaml

Lines changed: 5 additions & 86 deletions
Original file line numberDiff line numberDiff line change
@@ -1766,97 +1766,16 @@ metadata:
17661766
annotations:
17671767
olm.operatorframework.io/feature-set: experimental
17681768
rules:
1769-
- apiGroups:
1770-
- ""
1771-
resources:
1772-
- serviceaccounts/token
1773-
verbs:
1774-
- create
1775-
- apiGroups:
1776-
- ""
1777-
resources:
1778-
- serviceaccounts
1779-
verbs:
1780-
- get
1781-
- apiGroups:
1782-
- apiextensions.k8s.io
1783-
resources:
1784-
- customresourcedefinitions
1785-
verbs:
1786-
- get
1787-
- apiGroups:
1788-
- olm.operatorframework.io
1789-
resources:
1790-
- clustercatalogs
1791-
verbs:
1792-
- get
1793-
- list
1794-
- watch
1795-
- apiGroups:
1796-
- olm.operatorframework.io
1797-
resources:
1798-
- clusterextensions
1799-
verbs:
1800-
- get
1801-
- list
1802-
- patch
1803-
- update
1804-
- watch
1805-
- apiGroups:
1806-
- olm.operatorframework.io
1807-
resources:
1808-
- clusterextensions/finalizers
1809-
verbs:
1810-
- update
1811-
- apiGroups:
1812-
- olm.operatorframework.io
1813-
resources:
1814-
- clusterextensions/status
1815-
verbs:
1816-
- patch
1817-
- update
1818-
- apiGroups:
1819-
- rbac.authorization.k8s.io
1820-
resources:
1821-
- clusterrolebindings
1822-
- clusterroles
1823-
- rolebindings
1824-
- roles
1825-
verbs:
1826-
- list
1827-
- watch
18281769
- apiGroups:
18291770
- "*"
18301771
resources:
18311772
- "*"
18321773
verbs:
1833-
- list
1834-
- watch
1835-
- apiGroups:
1836-
- olm.operatorframework.io
1837-
resources:
1838-
- clusterextensionrevisions
1839-
verbs:
1840-
- create
1841-
- delete
1842-
- get
1843-
- list
1844-
- patch
1845-
- update
1846-
- watch
1847-
- apiGroups:
1848-
- olm.operatorframework.io
1849-
resources:
1850-
- clusterextensionrevisions/status
1851-
verbs:
1852-
- patch
1853-
- update
1854-
- apiGroups:
1855-
- olm.operatorframework.io
1856-
resources:
1857-
- clusterextensionrevisions/finalizers
1774+
- "*"
1775+
- nonResourceURLs:
1776+
- "*"
18581777
verbs:
1859-
- update
1778+
- "*"
18601779
---
18611780
# Source: olmv1/templates/rbac/clusterrolebinding-catalogd-manager-rolebinding.yml
18621781
apiVersion: rbac.authorization.k8s.io/v1
@@ -1924,7 +1843,7 @@ metadata:
19241843
labels:
19251844
app.kubernetes.io/name: operator-controller
19261845
app.kubernetes.io/part-of: olm
1927-
name: operator-controller-manager-admin-rolebinding
1846+
name: operator-controller-manager-rolebinding
19281847
roleRef:
19291848
apiGroup: rbac.authorization.k8s.io
19301849
kind: ClusterRole

0 commit comments

Comments
 (0)