Skip to content

fix(rbac): drop unused write permissions on nodes from clusterrole - #780

Open
magic-peach wants to merge 1 commit into
accuknox:devfrom
magic-peach:fix-clusterrole-node-write-perms
Open

magic-peach wants to merge 1 commit into
accuknox:devfrom
magic-peach:fix-clusterrole-node-write-perms

Conversation

@magic-peach

Copy link
Copy Markdown

Purpose of PR?:

The clusterrole grants create, update and delete on nodes along with every other watched resource, but the codebase only ever lists nodes to build cluster info, never writes to them. This splits nodes into their own rule with just get, list and watch.

Fixes #753

Does this PR introduce a breaking change?

No.

If the changes in this PR are manually verified, list down the scenarios covered::

Verified via YAML syntax check on the updated manifests, and by confirming nodes are only ever listed (never created, updated, or deleted) anywhere in the codebase.

Additional information for reviewer? :

None.

Checklist:

  • Bug fix. Fixes Refine RBAC permissions for discovery-engine clusterrole #753
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • This change requires a documentation update
  • PR Title follows the convention of <type>(<scope>): <subject>
  • Commit has unit tests
  • Commit has integration tests

The clusterrole grants create, update and delete on nodes along with
every other watched resource, but the codebase only ever lists nodes
to build cluster info, never writes to them. Split nodes into their
own rule with just get, list and watch.

Fixes accuknox#753

Signed-off-by: Akanksha Trehun <akankshatrehun@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Refine RBAC permissions for discovery-engine clusterrole

1 participant