Skip to content

Commit 757479b

Browse files
committed
fix(install): revert watch rbac
1 parent a07f0bb commit 757479b

2 files changed

Lines changed: 14 additions & 0 deletions

File tree

pkg/resources/config/rbac/descoped/operator-cluster-role.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -193,6 +193,7 @@ rules:
193193
- get
194194
- list
195195
- patch
196+
- watch
196197
# Service Accounts (dynamic SA creation)
197198
- apiGroups:
198199
- ""
@@ -203,6 +204,7 @@ rules:
203204
- delete
204205
- get
205206
- list
207+
- watch
206208
# Required to check if a ServiceAccount can access other namespaces resources
207209
- apiGroups:
208210
- authorization.k8s.io

pkg/resources/config/rbac/namespaced/operator-role.yaml

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -180,6 +180,17 @@ rules:
180180
verbs:
181181
- get
182182
- list
183+
# Service Accounts (dynamic SA creation)
184+
- apiGroups:
185+
- ""
186+
resources:
187+
- serviceaccounts
188+
verbs:
189+
- create
190+
- delete
191+
- get
192+
- list
193+
- watch
183194
# Roles and RoleBindings
184195
- apiGroups:
185196
- rbac.authorization.k8s.io
@@ -192,3 +203,4 @@ rules:
192203
- get
193204
- list
194205
- patch
206+
- watch

0 commit comments

Comments
 (0)