Skip to content

Conversation

YCShen1010
Copy link
Contributor

Summary:

  • Prunes excessive RBAC on the controller Role by dropping unused verbs and splitting pod access into its own rule
  • Restricts the controller ClusterRole to read/update webhook configs instead of full lifecycle control
  • Mirrors the RBAC in helm

Fix issue: https://github.ibm.com/IBMPrivateCloud/roadmap/issues/67915

Signed-off-by: YuChen <yuchen.shen@mail.utoronto.ca>
Signed-off-by: YuChen <yuchen.shen@mail.utoronto.ca>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant