Open vishvajit79 opened 3 months ago
Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).
View this failed invocation of the CLA check for more information.
For the most up to date status, view the checks section at the bottom of the pull request.
[APPROVALNOTIFIER] This PR is NOT APPROVED
This pull-request has been approved by: Once this PR has been reviewed and has the lgtm label, please assign alculquicondor for approval. For more information see the Kubernetes Code Review Process.
The full list of commands accepted by this bot can be found here.
Update cluster-role.yaml to remove the unnecessary RBAC rule for mpijobs-admin.
Hello,
Thank you for reviewing this PR. I have removed the line
rbac.authorization.kubeflow.org/aggregate-to-kubeflow-mpijobs-admin: "true"
from theclusterrole
as it was overriding thekubeflow-mpijobs-admin
role with thekubeflow-mpijobs-edit
role.To clarify, the
rbac.authorization.kubeflow.org/aggregate-to-kubeflow-mpijobs-admin
annotation is used to aggregate thekubeflow-mpijobs-admin
role to thekubeflow-mpijobs
namespace. However, the previous implementation of this annotation was overriding thekubeflow-mpijobs-admin
role with thekubeflow-mpijobs-edit
role, which is more restrictive.By removing this line, we are restoring the intended behavior of the
kubeflow-mpijobs-admin
role, allowing users with this role to manage MPI jobs in thekubeflow-mpijobs
namespace.Thank you for your attention to this matter.