Skip to content

Commit 786dda4

Browse files
Merge pull request #274 from JoelSpeed/azure-fine-grained-role
OCPCLOUD-2013: Move Azure Credentials Request to custom role
2 parents 1bcc8b7 + 53dbc5a commit 786dda4

File tree

1 file changed

+10
-2
lines changed

1 file changed

+10
-2
lines changed

manifests/0000_26_cloud-controller-manager-operator_14_credentialsrequest-azure.yaml

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,15 @@ spec:
1313
providerSpec:
1414
apiVersion: cloudcredential.openshift.io/v1
1515
kind: AzureProviderSpec
16-
roleBindings:
17-
- role: Contributor
16+
permissions:
17+
- Microsoft.Compute/virtualMachines/read
18+
- Microsoft.Network/loadBalancers/read
19+
- Microsoft.Network/loadBalancers/write
20+
- Microsoft.Network/networkInterfaces/read
21+
- Microsoft.Network/networkSecurityGroups/read
22+
- Microsoft.Network/networkSecurityGroups/write
23+
- Microsoft.Network/publicIPAddresses/join/action
24+
- Microsoft.Network/publicIPAddresses/read
25+
- Microsoft.Network/publicIPAddresses/write
1826
serviceAccountNames:
1927
- cloud-controller-manager

0 commit comments

Comments
 (0)