-
Notifications
You must be signed in to change notification settings - Fork 232
[OpenShift] Fix RBAC bugs #634
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
02595cf to
0d14f5e
Compare
|
/hold |
0d14f5e to
0ce6055
Compare
|
/retest |
|
/retest |
e49aabb to
d9de7e5
Compare
|
/hold cancel |
|
/lgtm |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: vdemeester The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
- Rename rolebinding created by RBAC reconciler to
'openshift-pipelines-edit' (was 'edit' earlier)
- Add mechanism to ensure that missing RBAC resources are recreated if
the RBAC installerSet is recreated during an upgrade.
- this ensures that RBAC in the version label in RBAC reconciled
namespaces are removed during an upgrade and the presence of RBAC
resources are verified
- Make TektonConfig reconciler listen to TektonInstallerSet events so
that it can recreate RBAC InstallerSet if it is deleted manually from
a cluster
- Add a mechanism to remove ownerReference and 'pipeline' sa subject
from 'edit' rolebinding in namespaces
- This ensures that operator upgrades won't delete/reset 'edit'
rolebinding in usernamespaces.
Signed-off-by: Nikhil Thomas <nikthoma@redhat.com>
d9de7e5 to
86bdf96
Compare
|
New changes are detected. LGTM label has been removed. |
|
/test pull-tekton-operator-integration-tests |
Signed-off-by: Nikhil Thomas nikthoma@redhat.com
Changes
Rename rolebinding created by RBAC reconciler to
'openshift-pipelines-edit' (was 'edit' earlier)
Add mechanism to ensure that missing RBAC resources are recreated if
the RBAC installerSet is recreated during an upgrade.
namespaces are removed during an upgrade and the presence of RBAC
resources are re-verified
Make TektonConfig reconciler listen to TektonInstallerSet events so
that it can recreate RBAC InstallerSet if it is deleted manually from
a cluster
Add a mechanism to remove ownerReference and 'pipeline' sa subject
from 'edit' rolebinding in namespaces
rolebinding in usernamespaces.
pipelineserviceaccount.Submitter Checklist
These are the criteria that every PR should meet, please check them off as you
review them:
See the contribution guide for more details.
Release Notes