Uploaded image for project: 'Red Hat Cluster Management Cloud Services'
  1. Red Hat Cluster Management Cloud Services
  2. CMCS-160

Create tailored clusterrole for syncer rather than using cluster-admin

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Major Major
    • None
    • None
    • Compute
    • None
    • Milestone 6

      Currently the service account created for the syncer uses the cluster-admin role. This is problematic because it's more permission than needed and also it means our controller needs to run as admin in order to create the cluster role binding to cluster-admin role. 

      We should create a clusterrole with just what is needed. See 
      https://github.com/kcp-dev/kcp/blob/main/pkg/cliplugins/workload/plugin/sync.go#L227
       

              rbobbitt@redhat.com Robin Bobbitt
              rbobbitt@redhat.com Robin Bobbitt
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: