diff --git a/helm-chart/zxporter/templates/zxporter-rbac.yaml b/helm-chart/zxporter/templates/zxporter-rbac.yaml index 5c796613..bb82871f 100644 --- a/helm-chart/zxporter/templates/zxporter-rbac.yaml +++ b/helm-chart/zxporter/templates/zxporter-rbac.yaml @@ -124,224 +124,230 @@ kind: ClusterRole metadata: name: devzero-zxporter-manager-role rules: - - apiGroups: - - apiextensions.k8s.io - resources: - - customresourcedefinitions - verbs: - - get - - list - - watch - - apiGroups: - - apiregistration.k8s.io - resources: - - apiservices - verbs: - - create - - delete - - get - - list - - patch - - update - - apiGroups: - - apps - resources: - - daemonsets - - deployments - - replicasets - - statefulsets - verbs: - - get - - list - - watch - - apiGroups: - - argoproj.io - resources: - - rollouts - verbs: - - get - - list - - watch - - apiGroups: - - autoscaling - resources: - - horizontalpodautoscalers - verbs: - - get - - list - - watch - - apiGroups: - - autoscaling.k8s.io - resources: - - verticalpodautoscalers - verbs: - - get - - list - - watch - - apiGroups: - - batch - resources: - - cronjobs - - jobs - verbs: - - get - - list - - watch - - apiGroups: - - "" - resources: - - configmaps - - endpoints - - events - - limitranges - - namespaces - - nodes - - persistentvolumeclaims - - persistentvolumes - - pods - - replicationcontrollers - - resourcequotas - - serviceaccounts - - services - verbs: - - get - - list - - watch - - apiGroups: - - "" - resources: - - nodes/metrics - - nodes/status - - pods/status - verbs: - - get - - apiGroups: - - datadoghq.com - resources: - - extendeddaemonsetreplicasets - verbs: - - get - - list - - watch - - apiGroups: - - devzero.io - resources: - - collectionpolicies - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - devzero.io - resources: - - collectionpolicies/finalizers - verbs: - - update - - apiGroups: - - devzero.io - resources: - - collectionpolicies/status - verbs: - - get - - patch - - update - - apiGroups: - - karpenter.k8s.aws - resources: - - awsnodetemplates - - ec2nodeclasses - verbs: - - get - - list - - watch - - apiGroups: - - karpenter.sh - resources: - - machines - - nodeclaims - - nodepools - - provisioners - verbs: - - get - - list - - watch - - apiGroups: - - keda.sh - resources: - - clustertriggerauthentications - - scaledjobs - - scaledobjects - - triggerauthentications - verbs: - - get - - list - - watch - - apiGroups: - - metrics.k8s.io - resources: - - nodes - - pods - verbs: - - get - - list - - watch - - apiGroups: - - networking.k8s.io - resources: - - ingressclasses - - ingresses - - networkpolicies - verbs: - - get - - list - - watch - - apiGroups: - - policy - resources: - - poddisruptionbudgets - verbs: - - get - - list - - watch - - apiGroups: - - rbac.authorization.k8s.io - resources: - - clusterrolebindings - - clusterroles - - role - - rolebindings - verbs: - - create - - delete - - get - - list - - patch - - update - - watch - - apiGroups: - - rbac.authorization.k8s.io - resources: - - roles - verbs: - - get - - list - - watch - - apiGroups: - - storage.k8s.io - resources: - - csidrivers - - csinodes - - csistoragecapacities - - storageclasses - - volumeattachments - verbs: - - get - - list - - watch +- apiGroups: + - "" + resources: + - configmaps + - endpoints + - events + - limitranges + - namespaces + - nodes + - persistentvolumeclaims + - persistentvolumes + - pods + - replicationcontrollers + - resourcequotas + - serviceaccounts + - services + verbs: + - get + - list + - watch +- apiGroups: + - "" + resources: + - nodes/metrics + - nodes/status + - pods/status + verbs: + - get +- apiGroups: + - apiextensions.k8s.io + resources: + - customresourcedefinitions + verbs: + - get + - list + - watch +- apiGroups: + - apiregistration.k8s.io + resources: + - apiservices + verbs: + - create + - get + - list + - patch + - update +- apiGroups: + - apps + resources: + - daemonsets + - deployments + - replicasets + - statefulsets + verbs: + - get + - list + - watch +- apiGroups: + - argoproj.io + resources: + - rollouts + verbs: + - get + - list + - watch +- apiGroups: + - autoscaling + resources: + - horizontalpodautoscalers + verbs: + - get + - list + - watch +- apiGroups: + - autoscaling.k8s.io + resources: + - verticalpodautoscalers + verbs: + - get + - list + - watch +- apiGroups: + - batch + resources: + - cronjobs + - jobs + verbs: + - get + - list + - watch +- apiGroups: + - datadoghq.com + resources: + - extendeddaemonsetreplicasets + verbs: + - get + - list + - watch +- apiGroups: + - devzero.io + resources: + - collectionpolicies + verbs: + - create + - delete + - get + - list + - patch + - update + - watch +- apiGroups: + - devzero.io + resources: + - collectionpolicies/finalizers + verbs: + - update +- apiGroups: + - devzero.io + resources: + - collectionpolicies/status + verbs: + - get + - patch + - update +- apiGroups: + - karpenter.k8s.aws + resources: + - awsnodetemplates + - ec2nodeclasses + verbs: + - get + - list + - watch +- apiGroups: + - karpenter.sh + resources: + - machines + - nodeclaims + - nodepools + - provisioners + verbs: + - get + - list + - watch +- apiGroups: + - keda.sh + resources: + - clustertriggerauthentications + - scaledjobs + - scaledobjects + - triggerauthentications + verbs: + - get + - list + - watch +- apiGroups: + - kubeflow.org + resources: + - notebooks + verbs: + - get + - list + - watch +- apiGroups: + - metrics.k8s.io + resources: + - nodes + - pods + verbs: + - get + - list + - watch +- apiGroups: + - networking.k8s.io + resources: + - ingressclasses + - ingresses + - networkpolicies + verbs: + - get + - list + - watch +- apiGroups: + - policy + resources: + - poddisruptionbudgets + verbs: + - get + - list + - watch +- apiGroups: + - rbac.authorization.k8s.io + resources: + - clusterrolebindings + - clusterroles + - role + - rolebindings + verbs: + - create + - get + - list + - patch + - update + - watch +- apiGroups: + - rbac.authorization.k8s.io + resources: + - roles + verbs: + - get + - list + - watch +- apiGroups: + - storage.k8s.io + resources: + - csidrivers + - csinodes + - csistoragecapacities + - storageclasses + - volumeattachments + verbs: + - get + - list + - watch --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole