mirror of
https://github.com/Infisical/infisical.git
synced 2026-01-09 23:48:05 -05:00
34 lines
848 B
YAML
34 lines
848 B
YAML
# This rule is not used by the project k8-operator itself.
|
|
# It is provided to allow the cluster admin to help manage permissions for users.
|
|
#
|
|
# Grants permissions to create, update, and delete resources within the secrets.infisical.com.
|
|
# This role is intended for users who need to manage these resources
|
|
# but should not control RBAC or manage permissions for others.
|
|
|
|
apiVersion: rbac.authorization.k8s.io/v1
|
|
kind: ClusterRole
|
|
metadata:
|
|
labels:
|
|
app.kubernetes.io/name: k8-operator
|
|
app.kubernetes.io/managed-by: kustomize
|
|
name: infisicaldynamicsecret-editor-role
|
|
rules:
|
|
- apiGroups:
|
|
- secrets.infisical.com
|
|
resources:
|
|
- infisicaldynamicsecrets
|
|
verbs:
|
|
- create
|
|
- delete
|
|
- get
|
|
- list
|
|
- patch
|
|
- update
|
|
- watch
|
|
- apiGroups:
|
|
- secrets.infisical.com
|
|
resources:
|
|
- infisicaldynamicsecrets/status
|
|
verbs:
|
|
- get
|