update rbac for secret#152
Conversation
|
Welcome @hoyho! |
|
Hi @hoyho. Thanks for your PR. I'm waiting for a kubernetes-csi or kubernetes member to verify that this patch is reasonable to test. If it is, they should reply with Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
|
Does the external-attacher need other permission? Currently it has verbs: ["get", "list"] @jsafrane |
| - apiGroups: [""] | ||
| resources: ["nodes"] | ||
| verbs: ["get", "list", "watch"] | ||
| - apiGroups: [""] |
There was a problem hiding this comment.
Can we make these optional with a comment? Not all drivers are going to need it and we want to reduce rbac permissions as much as possible by default.
There was a problem hiding this comment.
Ok, sounds good. Since there's no secret permission by default, should we also add a note at https://github.com/kubernetes-csi/docs/blob/master/book/src/secrets-and-credentials.md#secrets-and-credentials to remind people to enable here?
|
/ok-to-test |
3b63aa6 to
a5a763d
Compare
a5a763d to
2e5b1be
Compare
|
/lgtm |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: hoyho, msau42 The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
What type of PR is this?
/kind bug
What this PR does / why we need it:
Attach will be fail when StorageClass specific parameters
csi.storage.k8s.io/controller-publish-secret-nameandcsi.storage.k8s.io/controller-publish-secret-namespaceWhich issue(s) this PR fixes:
Fixes #88
Special notes for your reviewer:
Does this PR introduce a user-facing change?: