-
Bug
-
Resolution: Done
-
Normal
-
TP1
-
None
-
Serverless Sprint 174
A non-cluster-admin can create a KnativeServing CR. Obviously only the knative-serving/knative-serving CR matters, but if a non-cluster-admin manages to create that before the cluster admin does then that user can control a cluster-wide Knative install.
We should change the RBAC on the KnativeServing resource so that only cluster admins are granted permission to create them out of the box.
- relates to
-
SRVKS-308 KnativeServing CR should move to operator.knative.dev API Group
-
- Closed
-