Open shiron-babi opened 3 months ago
The operator manager cluster role seems to have very permissive permissions. Mainly the first part seems something that should be defined differently.
- apiGroups: [ "" ] resources: [ "configmaps" ] verbs: [ "create", "delete", "get", "list", "patch", "update", "watch" ] - apiGroups: [ "" ] resources: [ "events" ] verbs: [ "create", "patch" ] - apiGroups: [ "" ] resources: [ "namespaces" ] verbs: [ "get","list","patch","update","watch" ] - apiGroups: [ "" ] resources: [ "serviceaccounts" ] verbs: [ "create","delete","get","list","patch","update","watch" ] - apiGroups: [ "" ] resources: [ "services" ] verbs: [ "create","delete","get","list","patch","update","watch" ] - apiGroups: [ "apps" ] resources: [ "daemonsets" ] verbs: [ "create","delete","get","list","patch","update","watch" ] - apiGroups: [ "apps" ] resources: [ "deployments" ] verbs: [ "create","delete","get","list","patch","update","watch" ]
Is this configuration legitimate, and is it really needed?
The operator manager cluster role seems to have very permissive permissions. Mainly the first part seems something that should be defined differently.
Is this configuration legitimate, and is it really needed?