Merge pull request #103704 from robscott/endpoints-write-remove

Remove Endpoints write access from aggregated edit role
This commit is contained in:
Kubernetes Prow Robot 2021-07-19 20:57:31 -07:00 committed by GitHub
commit e847b849c4
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
2 changed files with 1 additions and 2 deletions

View File

@ -285,7 +285,7 @@ func ClusterRoles() []rbacv1.ClusterRole {
rbacv1helpers.NewRule(Write...).Groups(legacyGroup).Resources("pods", "pods/attach", "pods/proxy", "pods/exec", "pods/portforward").RuleOrDie(), rbacv1helpers.NewRule(Write...).Groups(legacyGroup).Resources("pods", "pods/attach", "pods/proxy", "pods/exec", "pods/portforward").RuleOrDie(),
rbacv1helpers.NewRule(Write...).Groups(legacyGroup).Resources("replicationcontrollers", "replicationcontrollers/scale", "serviceaccounts", rbacv1helpers.NewRule(Write...).Groups(legacyGroup).Resources("replicationcontrollers", "replicationcontrollers/scale", "serviceaccounts",
"services", "services/proxy", "endpoints", "persistentvolumeclaims", "configmaps", "secrets", "events").RuleOrDie(), "services", "services/proxy", "persistentvolumeclaims", "configmaps", "secrets", "events").RuleOrDie(),
rbacv1helpers.NewRule(Write...).Groups(appsGroup).Resources( rbacv1helpers.NewRule(Write...).Groups(appsGroup).Resources(
"statefulsets", "statefulsets/scale", "statefulsets", "statefulsets/scale",

View File

@ -128,7 +128,6 @@ items:
- "" - ""
resources: resources:
- configmaps - configmaps
- endpoints
- events - events
- persistentvolumeclaims - persistentvolumeclaims
- replicationcontrollers - replicationcontrollers