From eff81d5ee820940c2fb7e444828e4e94a2e3377c Mon Sep 17 00:00:00 2001 From: Dmytro Alieksieiev <1865999+dragoangel@users.noreply.github.com> Date: Thu, 22 Aug 2024 18:50:15 +0200 Subject: [PATCH] helm: Always add nodes read permissions to provisioner ClusterRole Signed-off-by: Dmytro Alieksieiev <1865999+dragoangel@users.noreply.github.com> --- charts/ceph-csi-rbd/templates/provisioner-clusterrole.yaml | 2 -- 1 file changed, 2 deletions(-) diff --git a/charts/ceph-csi-rbd/templates/provisioner-clusterrole.yaml b/charts/ceph-csi-rbd/templates/provisioner-clusterrole.yaml index ad79fd70712c..b2c01ae6250d 100644 --- a/charts/ceph-csi-rbd/templates/provisioner-clusterrole.yaml +++ b/charts/ceph-csi-rbd/templates/provisioner-clusterrole.yaml @@ -81,14 +81,12 @@ rules: resources: ["persistentvolumeclaims/status"] verbs: ["update", "patch"] {{- end }} -{{- if .Values.topology.domainLabels }} - apiGroups: [""] resources: ["nodes"] verbs: ["get", "list","watch"] - apiGroups: ["storage.k8s.io"] resources: ["csinodes"] verbs: ["get", "list", "watch"] -{{- end }} - apiGroups: [""] resources: ["serviceaccounts/token"] verbs: ["create"]