operator RBAC needs podsecuritypolicy to grant it to postgres-pod
This commit is contained in:
		
							parent
							
								
									91475ab918
								
							
						
					
					
						commit
						b0018b6ecf
					
				|  | @ -134,6 +134,18 @@ rules: | ||||||
|   - get |   - get | ||||||
|   - list |   - list | ||||||
|   - patch |   - patch | ||||||
|  | # to CRUD cron jobs for logical backups | ||||||
|  | - apiGroups: | ||||||
|  |   - batch | ||||||
|  |   resources: | ||||||
|  |   - cronjobs | ||||||
|  |   verbs: | ||||||
|  |   - create | ||||||
|  |   - delete | ||||||
|  |   - get | ||||||
|  |   - list | ||||||
|  |   - patch | ||||||
|  |   - update | ||||||
| # to get namespaces operator resources can run in | # to get namespaces operator resources can run in | ||||||
| - apiGroups: | - apiGroups: | ||||||
|   - "" |   - "" | ||||||
|  | @ -166,16 +178,13 @@ rules: | ||||||
|   verbs: |   verbs: | ||||||
|   - get |   - get | ||||||
|   - create |   - create | ||||||
| # to CRUD cron jobs for logical backups | # to grant privilege to run privileged pods | ||||||
| - apiGroups: | - apiGroups: | ||||||
|   - batch |   - extensions | ||||||
|   resources: |   resources: | ||||||
|   - cronjobs |   - podsecuritypolicies | ||||||
|  |   resourceNames: | ||||||
|  |   - privileged | ||||||
|   verbs: |   verbs: | ||||||
|   - create |   - use | ||||||
|   - delete |  | ||||||
|   - get |  | ||||||
|   - list |  | ||||||
|   - patch |  | ||||||
|   - update |  | ||||||
| {{ end }} | {{ end }} | ||||||
|  |  | ||||||
|  | @ -135,6 +135,18 @@ rules: | ||||||
|   - get |   - get | ||||||
|   - list |   - list | ||||||
|   - patch |   - patch | ||||||
|  | # to CRUD cron jobs for logical backups | ||||||
|  | - apiGroups: | ||||||
|  |   - batch | ||||||
|  |   resources: | ||||||
|  |   - cronjobs | ||||||
|  |   verbs: | ||||||
|  |   - create | ||||||
|  |   - delete | ||||||
|  |   - get | ||||||
|  |   - list | ||||||
|  |   - patch | ||||||
|  |   - update | ||||||
| # to get namespaces operator resources can run in | # to get namespaces operator resources can run in | ||||||
| - apiGroups: | - apiGroups: | ||||||
|   - "" |   - "" | ||||||
|  | @ -167,18 +179,15 @@ rules: | ||||||
|   verbs: |   verbs: | ||||||
|   - get |   - get | ||||||
|   - create |   - create | ||||||
| # to CRUD cron jobs for logical backups | # to grant privilege to run privileged pods | ||||||
| - apiGroups: | - apiGroups: | ||||||
|   - batch |   - extensions | ||||||
|   resources: |   resources: | ||||||
|   - cronjobs |   - podsecuritypolicies | ||||||
|  |   resourceNames: | ||||||
|  |   - privileged | ||||||
|   verbs: |   verbs: | ||||||
|   - create |   - use | ||||||
|   - delete |  | ||||||
|   - get |  | ||||||
|   - list |  | ||||||
|   - patch |  | ||||||
|   - update |  | ||||||
| 
 | 
 | ||||||
| --- | --- | ||||||
| apiVersion: rbac.authorization.k8s.io/v1 | apiVersion: rbac.authorization.k8s.io/v1 | ||||||
|  |  | ||||||
		Loading…
	
		Reference in New Issue