From f2a99bb76931d4a230afe19daaafea1401831adb Mon Sep 17 00:00:00 2001 From: Martin Linkhorst Date: Tue, 30 Jan 2024 16:59:10 +0100 Subject: [PATCH] isolate permissions of e2e stackset-controller to its own namespace to avoid clashes (#567) --- e2e/apply/rbac.yaml | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/e2e/apply/rbac.yaml b/e2e/apply/rbac.yaml index 455961e7..f77e19da 100644 --- a/e2e/apply/rbac.yaml +++ b/e2e/apply/rbac.yaml @@ -5,7 +5,7 @@ metadata: name: stackset-controller --- apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRole +kind: Role metadata: name: stackset-controller rules: @@ -103,14 +103,13 @@ rules: - patch --- apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRoleBinding +kind: RoleBinding metadata: name: stackset-controller-e2e roleRef: apiGroup: rbac.authorization.k8s.io - kind: ClusterRole + kind: Role name: stackset-controller subjects: - kind: ServiceAccount name: stackset-controller - namespace: {{{NAMESPACE}}}