Skip to content

Commit 245436c

Browse files
authored
add cluster-admin permissions to o-c SA temporarily (#1073)
Signed-off-by: everettraven <everettraven@gmail.com>
1 parent 95b9f0d commit 245436c

File tree

2 files changed

+9
-0
lines changed

2 files changed

+9
-0
lines changed

config/base/rbac/role.yaml

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,12 @@ kind: ClusterRole
44
metadata:
55
name: manager-role
66
rules:
7+
- apiGroups:
8+
- '*'
9+
resources:
10+
- '*'
11+
verbs:
12+
- '*'
713
- apiGroups:
814
- apiextensions.k8s.io
915
resources:

internal/controllers/clusterextension_controller.go

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -119,6 +119,9 @@ type Preflight interface {
119119
//+kubebuilder:rbac:groups=core,resources=serviceaccounts/token,verbs=create
120120
//+kubebuilder:rbac:groups=apiextensions.k8s.io,resources=customresourcedefinitions,verbs=get
121121

122+
// TODO: Remove these permissions as part of resolving https://github.com/operator-framework/operator-controller/issues/975
123+
//+kubebuilder:rbac:groups=*,resources=*,verbs=*
124+
122125
//+kubebuilder:rbac:groups=catalogd.operatorframework.io,resources=clustercatalogs,verbs=list;watch
123126
//+kubebuilder:rbac:groups=catalogd.operatorframework.io,resources=catalogmetadata,verbs=list;watch
124127

0 commit comments

Comments
 (0)