From da550071802a768acbf024e612b7acdab3c0b186 Mon Sep 17 00:00:00 2001 From: Mikhail Zholobov Date: Fri, 13 Sep 2024 10:30:20 +0200 Subject: [PATCH] Revert the deletion of RBAC rule "allow to get any resource" Signed-off-by: Mikhail Zholobov --- config/rbac/role.yaml | 6 ++++++ controllers/keda/scaledobject_controller.go | 1 + 2 files changed, 7 insertions(+) diff --git a/config/rbac/role.yaml b/config/rbac/role.yaml index e7fd6a8c627..9d8e7ce79d4 100644 --- a/config/rbac/role.yaml +++ b/config/rbac/role.yaml @@ -45,6 +45,12 @@ rules: verbs: - list - watch +- apiGroups: + - '*' + resources: + - '*' + verbs: + - get - apiGroups: - admissionregistration.k8s.io resources: diff --git a/controllers/keda/scaledobject_controller.go b/controllers/keda/scaledobject_controller.go index ec7ac5f1421..f7b7322d7b8 100755 --- a/controllers/keda/scaledobject_controller.go +++ b/controllers/keda/scaledobject_controller.go @@ -61,6 +61,7 @@ import ( // +kubebuilder:rbac:groups="",resources=pods;services;services;secrets;external,verbs=get;list;watch // +kubebuilder:rbac:groups="apps",resources=deployments/scale;statefulsets/scale,verbs=get;list;watch;update;patch // +kubebuilder:rbac:groups="",resources="serviceaccounts",verbs=list;watch +// +kubebuilder:rbac:groups="*",resources="*",verbs=get // +kubebuilder:rbac:groups="apps",resources=deployments;statefulsets,verbs=list;watch // +kubebuilder:rbac:groups="coordination.k8s.io",namespace=keda,resources=leases,verbs=get;list;watch;update;patch;create;delete // +kubebuilder:rbac:groups="",resources="limitranges",verbs=list;watch