Skip to content

Commit d7f7eaf

Browse files
committed
fix up template instance controller permissions
1 parent 577d6ce commit d7f7eaf

File tree

3 files changed

+0
-18
lines changed

3 files changed

+0
-18
lines changed

pkg/cmd/server/bootstrappolicy/controller_policy.go

-1
Original file line numberDiff line numberDiff line change
@@ -156,7 +156,6 @@ func init() {
156156
ObjectMeta: metav1.ObjectMeta{Name: saRolePrefix + InfraTemplateInstanceControllerServiceAccountName},
157157
Rules: []rbac.PolicyRule{
158158
rbac.NewRule("create").Groups(kAuthzGroup).Resources("subjectaccessreviews").RuleOrDie(),
159-
rbac.NewRule("get", "list", "watch").Groups(templateGroup).Resources("subjectaccessreviews").RuleOrDie(),
160159
rbac.NewRule("update").Groups(templateGroup).Resources("templateinstances/status").RuleOrDie(),
161160
rbac.NewRule("update").Groups(templateGroup).Resources("templateinstances/finalizers").RuleOrDie(),
162161
},

test/testdata/bootstrappolicy/bootstrap_cluster_roles.yaml

-8
Original file line numberDiff line numberDiff line change
@@ -3106,14 +3106,6 @@ items:
31063106
- subjectaccessreviews
31073107
verbs:
31083108
- create
3109-
- apiGroups:
3110-
- template.openshift.io
3111-
resources:
3112-
- subjectaccessreviews
3113-
verbs:
3114-
- get
3115-
- list
3116-
- watch
31173109
- apiGroups:
31183110
- template.openshift.io
31193111
resources:

test/testdata/bootstrappolicy/bootstrap_policy_file.yaml

-9
Original file line numberDiff line numberDiff line change
@@ -3389,15 +3389,6 @@ items:
33893389
- subjectaccessreviews
33903390
verbs:
33913391
- create
3392-
- apiGroups:
3393-
- template.openshift.io
3394-
attributeRestrictions: null
3395-
resources:
3396-
- subjectaccessreviews
3397-
verbs:
3398-
- get
3399-
- list
3400-
- watch
34013392
- apiGroups:
34023393
- template.openshift.io
34033394
attributeRestrictions: null

0 commit comments

Comments
 (0)