Skip to content

Commit 64926a3

Browse files
committed
fix libsonnet to add roles
1 parent a601d33 commit 64926a3

File tree

2 files changed

+20
-4
lines changed

2 files changed

+20
-4
lines changed

examples/autosharding/cluster-role.yaml

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -108,3 +108,11 @@ rules:
108108
verbs:
109109
- list
110110
- watch
111+
- apiGroups:
112+
- rbac.authorization.k8s.io
113+
resources:
114+
- clusterroles
115+
- roles
116+
verbs:
117+
- list
118+
- watch

jsonnet/kube-state-metrics/kube-state-metrics.libsonnet

Lines changed: 12 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -145,7 +145,15 @@
145145
],
146146
verbs: ['list', 'watch'],
147147
},
148-
];
148+
{
149+
apiGroups: ['rbac.authorization.k8s.io'],
150+
resources: [
151+
'clusterroles',
152+
'roles',
153+
],
154+
verbs: ['list', 'watch'],
155+
},
156+
];
149157

150158
{
151159
apiVersion: 'rbac.authorization.k8s.io/v1',
@@ -164,9 +172,9 @@
164172
{ name: 'http-metrics', containerPort: 8080 },
165173
{ name: 'telemetry', containerPort: 8081 },
166174
],
167-
securityContext: {
168-
runAsUser: 65534,
169-
allowPrivilegeEscalation: false,
175+
securityContext: {
176+
runAsUser: 65534,
177+
allowPrivilegeEscalation: false,
170178
readOnlyRootFilesystem: true,
171179
capabilities: { drop: ['ALL'] },
172180
},

0 commit comments

Comments
 (0)