allow sarapprover to create subject access reviews

This commit is contained in:
Mike Danese 2017-06-01 09:16:53 -07:00
parent ae91ecb62e
commit f533bf729f
2 changed files with 7 additions and 0 deletions

View File

@ -277,6 +277,7 @@ func init() {
Rules: []rbac.PolicyRule{ Rules: []rbac.PolicyRule{
rbac.NewRule("get", "list", "watch").Groups(certificatesGroup).Resources("certificatesigningrequests").RuleOrDie(), rbac.NewRule("get", "list", "watch").Groups(certificatesGroup).Resources("certificatesigningrequests").RuleOrDie(),
rbac.NewRule("update").Groups(certificatesGroup).Resources("certificatesigningrequests/status", "certificatesigningrequests/approval").RuleOrDie(), rbac.NewRule("update").Groups(certificatesGroup).Resources("certificatesigningrequests/status", "certificatesigningrequests/approval").RuleOrDie(),
rbac.NewRule("create").Groups(authorizationGroup).Resources("subjectaccessreviews").RuleOrDie(),
eventsRule(), eventsRule(),
}, },
}) })

View File

@ -73,6 +73,12 @@ items:
- certificatesigningrequests/status - certificatesigningrequests/status
verbs: verbs:
- update - update
- apiGroups:
- authorization.k8s.io
resources:
- subjectaccessreviews
verbs:
- create
- apiGroups: - apiGroups:
- "" - ""
resources: resources: