From e0cfc58bffdac1db2e30cfd859bfbbcdd9aff0b4 Mon Sep 17 00:00:00 2001 From: Roi Glinik Date: Thu, 25 Dec 2025 12:35:03 +0200 Subject: [PATCH 1/2] Revert service role to use resource names and not * access Signed-off-by: Roi Glinik --- .../templates/holmesgpt-service-account.yaml | 124 ++++++++++++++++-- 1 file changed, 115 insertions(+), 9 deletions(-) diff --git a/helm/holmes/templates/holmesgpt-service-account.yaml b/helm/holmes/templates/holmesgpt-service-account.yaml index e9cf813474..c818760c6b 100644 --- a/helm/holmes/templates/holmesgpt-service-account.yaml +++ b/helm/holmes/templates/holmesgpt-service-account.yaml @@ -185,7 +185,24 @@ rules: - apiGroups: - monitoring.coreos.com resources: - - "*" + - alertmanagers + - alertmanagers/finalizers + - alertmanagers/status + - alertmanagerconfigs + - prometheuses + - prometheuses/finalizers + - prometheuses/status + - prometheusagents + - prometheusagents/finalizers + - prometheusagents/status + - thanosrulers + - thanosrulers/finalizers + - thanosrulers/status + - scrapeconfigs + - servicemonitors + - podmonitors + - probes + - prometheusrules verbs: - get - list @@ -194,7 +211,18 @@ rules: - apiGroups: - argoproj.io resources: - - "*" + - applications + - applicationsets + - appprojects + - workflows + - workflowtemplates + - cronworkflows + - rollouts + - analysisruns + - analysistemplates + - experiments + - eventsources + - sensors verbs: - get - list @@ -203,11 +231,38 @@ rules: {{- if .Values.crdPermissions.flux }} - apiGroups: - source.toolkit.fluxcd.io + resources: + - gitrepositories + - helmrepositories + - helmcharts + - buckets + - ocirepositories + verbs: + - get + - list + - watch + - apiGroups: - kustomize.toolkit.fluxcd.io + resources: + - kustomizations + verbs: + - get + - list + - watch + - apiGroups: - helm.toolkit.fluxcd.io + resources: + - helmreleases + verbs: + - get + - list + - watch + - apiGroups: - notification.toolkit.fluxcd.io resources: - - "*" + - alerts + - providers + - receivers verbs: - get - list @@ -217,7 +272,14 @@ rules: - apiGroups: - kafka.strimzi.io resources: - - "*" + - kafkas + - kafkatopics + - kafkausers + - kafkaconnects + - kafkaconnectors + - kafkamirrormakers + - kafkabridges + - kafkarebalances verbs: - get - list @@ -227,7 +289,10 @@ rules: - apiGroups: - keda.sh resources: - - "*" + - scaledobjects + - scaledjobs + - triggerauthentications + - clustertriggerauthentications verbs: - get - list @@ -236,9 +301,19 @@ rules: {{- if .Values.crdPermissions.crossplane }} - apiGroups: - pkg.crossplane.io + resources: + - providers + - configurations + - functions + verbs: + - get + - list + - watch + - apiGroups: - apiextensions.crossplane.io resources: - - "*" + - compositions + - compositeresourcedefinitions verbs: - get - list @@ -247,9 +322,24 @@ rules: {{- if .Values.crdPermissions.istio }} - apiGroups: - networking.istio.io + resources: + - virtualservices + - destinationrules + - gateways + - serviceentries + - sidecars + - workloadentries + - workloadgroups + - proxyconfigs + - envoyfilters + verbs: + - get + - list + - watch + - apiGroups: - telemetry.istio.io resources: - - "*" + - telemetries verbs: - get - list @@ -259,7 +349,14 @@ rules: - apiGroups: - gateway.networking.k8s.io resources: - - "*" + - gatewayclasses + - gateways + - httproutes + - tcproutes + - tlsroutes + - udproutes + - grpcroutes + - referencegrants verbs: - get - list @@ -269,7 +366,16 @@ rules: - apiGroups: - velero.io resources: - - "*" + - backups + - restores + - schedules + - backupstoragelocations + - volumesnapshotlocations + - podvolumebackups + - podvolumerestores + - downloadrequests + - deletebackuprequests + - serverstatusrequests verbs: - get - list From fa468d6bcd0ccc8016d04d49aa6bc5e5457e08cd Mon Sep 17 00:00:00 2001 From: Roi Glinik Date: Thu, 25 Dec 2025 12:42:04 +0200 Subject: [PATCH 2/2] add also external secrets Signed-off-by: Roi Glinik --- docs/data-sources/permissions.md | 2 ++ .../holmes/templates/holmesgpt-service-account.yaml | 13 +++++++++++++ helm/holmes/values.yaml | 3 ++- 3 files changed, 17 insertions(+), 1 deletion(-) diff --git a/docs/data-sources/permissions.md b/docs/data-sources/permissions.md index 72945e55a8..28db861e89 100644 --- a/docs/data-sources/permissions.md +++ b/docs/data-sources/permissions.md @@ -21,6 +21,7 @@ HolmesGPT includes read-only permissions for common Kubernetes operators and too istio: true gatewayApi: true velero: true + externalSecrets: true ``` === "Robusta Helm Chart" @@ -37,6 +38,7 @@ HolmesGPT includes read-only permissions for common Kubernetes operators and too istio: true gatewayApi: true velero: true + externalSecrets: true ``` ## Adding Custom Permissions diff --git a/helm/holmes/templates/holmesgpt-service-account.yaml b/helm/holmes/templates/holmesgpt-service-account.yaml index c818760c6b..c0ab7b743c 100644 --- a/helm/holmes/templates/holmesgpt-service-account.yaml +++ b/helm/holmes/templates/holmesgpt-service-account.yaml @@ -381,6 +381,19 @@ rules: - list - watch {{- end }} +{{- if .Values.crdPermissions.externalSecrets }} + - apiGroups: + - external-secrets.io + resources: + - externalsecrets + - secretstores + - clustersecretstores + - clusterexternalsecrets + verbs: + - get + - list + - watch +{{- end }} --- apiVersion: v1 diff --git a/helm/holmes/values.yaml b/helm/holmes/values.yaml index 4edc4a905b..1c5ea5d294 100644 --- a/helm/holmes/values.yaml +++ b/helm/holmes/values.yaml @@ -39,7 +39,8 @@ crdPermissions: crossplane: true istio: true gatewayApi: true - velero: true + velero: true + externalSecrets: true enablePostProcessing: false postProcessingPrompt: "builtin://generic_post_processing.jinja2"