Open xiangjingli opened 4 years ago
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.
This still seems to be a problem.
Hi @joelanford do you have any insight around this area? Thanks.
Bug Report
After installing an operator, one edit cluster role is generated by OLM, where
create
verb is added. That allows users with the the edit role can create new resources.What did you do?
Multicluster Subscription Operator
from operator hub in Openshift.create
verbWhat did you expect to see?
It seems edit role user should not be allowed to create new resources. On the other hand, we noticed that the
create
permission is widely applied in all openshift edit roles e.g.system:openshift:aggregate-to-edit
Could someone clarify if it is by Openshift/OLM Design?