164 lines
4.3 KiB
YAML
164 lines
4.3 KiB
YAML
{{- if and .Values.rbac.create .Values.createGlobalResources -}}
|
|
apiVersion: rbac.authorization.k8s.io/v1
|
|
kind: ClusterRole
|
|
metadata:
|
|
name: strimzi-cluster-operator-namespaced
|
|
labels:
|
|
app: {{ template "strimzi.name" . }}
|
|
chart: {{ template "strimzi.chart" . }}
|
|
component: role
|
|
release: {{ .Release.Name }}
|
|
heritage: {{ .Release.Service }}
|
|
rules:
|
|
# Resources in this role are used by the operator based on an operand being deployed in some namespace. When needed, you
|
|
# can deploy the operator as a cluster-wide operator. But grant the rights listed in this role only on the namespaces
|
|
# where the operands will be deployed. That way, you can limit the access the operator has to other namespaces where it
|
|
# does not manage any clusters.
|
|
- apiGroups:
|
|
- "rbac.authorization.k8s.io"
|
|
resources:
|
|
# The cluster operator needs to access and manage rolebindings to grant Strimzi components cluster permissions
|
|
- rolebindings
|
|
verbs:
|
|
- get
|
|
- list
|
|
- watch
|
|
- create
|
|
- delete
|
|
- patch
|
|
- update
|
|
- apiGroups:
|
|
- "rbac.authorization.k8s.io"
|
|
resources:
|
|
# The cluster operator needs to access and manage roles to grant the entity operator permissions
|
|
- roles
|
|
verbs:
|
|
- get
|
|
- list
|
|
- watch
|
|
- create
|
|
- delete
|
|
- patch
|
|
- update
|
|
- apiGroups:
|
|
- ""
|
|
resources:
|
|
# The cluster operator needs to access and delete pods, this is to allow it to monitor pod health and coordinate rolling updates
|
|
- pods
|
|
# The cluster operator needs to access and manage service accounts to grant Strimzi components cluster permissions
|
|
- serviceaccounts
|
|
# The cluster operator needs to access and manage config maps for Strimzi components configuration
|
|
- configmaps
|
|
# The cluster operator needs to access and manage services and endpoints to expose Strimzi components to network traffic
|
|
- services
|
|
- endpoints
|
|
# The cluster operator needs to access and manage secrets to handle credentials
|
|
- secrets
|
|
# The cluster operator needs to access and manage persistent volume claims to bind them to Strimzi components for persistent data
|
|
- persistentvolumeclaims
|
|
verbs:
|
|
- get
|
|
- list
|
|
- watch
|
|
- create
|
|
- delete
|
|
- patch
|
|
- update
|
|
- apiGroups:
|
|
- "apps"
|
|
resources:
|
|
# The cluster operator needs to access and manage deployments to run deployment based Strimzi components
|
|
- deployments
|
|
# The cluster operator needs to access replica-sets to manage Strimzi components and to determine error states
|
|
- replicasets
|
|
verbs:
|
|
- get
|
|
- list
|
|
- watch
|
|
- create
|
|
- delete
|
|
- patch
|
|
- update
|
|
- apiGroups:
|
|
- "apps"
|
|
resources:
|
|
# The Cluster Operator needs to scale Deployments while migrating Connect and Mirror Maker 2 clusters from Deployments to StrimziPodSets
|
|
- deployments/scale
|
|
verbs:
|
|
- get
|
|
- patch
|
|
- update
|
|
- apiGroups:
|
|
- "events.k8s.io" # new events api, used by cluster operator
|
|
resources:
|
|
# The cluster operator needs to be able to create events
|
|
- events
|
|
verbs:
|
|
- create
|
|
- apiGroups:
|
|
# Kafka Connect Build on OpenShift requirement
|
|
- build.openshift.io
|
|
resources:
|
|
- buildconfigs
|
|
- buildconfigs/instantiate
|
|
- builds
|
|
verbs:
|
|
- get
|
|
- list
|
|
- watch
|
|
- create
|
|
- delete
|
|
- patch
|
|
- update
|
|
- apiGroups:
|
|
- networking.k8s.io
|
|
resources:
|
|
# The cluster operator needs to access and manage network policies to lock down communication between Strimzi components
|
|
- networkpolicies
|
|
# The cluster operator needs to access and manage ingresses which allow external access to the services in a cluster
|
|
- ingresses
|
|
verbs:
|
|
- get
|
|
- list
|
|
- watch
|
|
- create
|
|
- delete
|
|
- patch
|
|
- update
|
|
- apiGroups:
|
|
- route.openshift.io
|
|
resources:
|
|
# The cluster operator needs to access and manage routes to expose Strimzi components for external access
|
|
- routes
|
|
- routes/custom-host
|
|
verbs:
|
|
- get
|
|
- list
|
|
- watch
|
|
- create
|
|
- delete
|
|
- patch
|
|
- update
|
|
- apiGroups:
|
|
- image.openshift.io
|
|
resources:
|
|
# The cluster operator needs to verify the image stream when used for Kafka Connect image build
|
|
- imagestreams
|
|
verbs:
|
|
- get
|
|
- apiGroups:
|
|
- policy
|
|
resources:
|
|
# The cluster operator needs to access and manage pod disruption budgets this limits the number of concurrent disruptions
|
|
# that a Strimzi component experiences, allowing for higher availability
|
|
- poddisruptionbudgets
|
|
verbs:
|
|
- get
|
|
- list
|
|
- watch
|
|
- create
|
|
- delete
|
|
- patch
|
|
- update
|
|
{{- end -}}
|