Tweak roles to fix permission errors #398
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There are two issues here; first, there was a missing permission to create events in the lease namespace if the lease namespace differs from
.Values.app.certmanager.namespace
. That was observed with the below error:Second, the permissions for creating the dynamic istiod cert were tied to the wrong namespace.
.Values.app.certmanager.namespace
isn't always the same as.Values.app.istio.namespace
.