allow sarapprover to create subject access reviews

This commit is contained in:
Mike Danese 2017-06-01 09:16:53 -07:00
parent ae91ecb62e
commit f533bf729f
2 changed files with 7 additions and 0 deletions

View File

@ -277,6 +277,7 @@ func init() {
Rules: []rbac.PolicyRule{
rbac.NewRule("get", "list", "watch").Groups(certificatesGroup).Resources("certificatesigningrequests").RuleOrDie(),
rbac.NewRule("update").Groups(certificatesGroup).Resources("certificatesigningrequests/status", "certificatesigningrequests/approval").RuleOrDie(),
rbac.NewRule("create").Groups(authorizationGroup).Resources("subjectaccessreviews").RuleOrDie(),
eventsRule(),
},
})

View File

@ -73,6 +73,12 @@ items:
- certificatesigningrequests/status
verbs:
- update
- apiGroups:
- authorization.k8s.io
resources:
- subjectaccessreviews
verbs:
- create
- apiGroups:
- ""
resources: