OCPBUGS-18132: Add patch for allowing configmap updates via clusterrole#396
Conversation
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: gnufied The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
| - patch | ||
| - update |
There was a problem hiding this comment.
This allows the vSphere CSI driver operator to patch any pod and ConfigMap in any namespace. IMO it's too broad.
It should allow only selected ConfigMap in openshift-config-managed namespace, i.e. a Role could be better. And definitely decoupled from Pods.
There was a problem hiding this comment.
Moved this to use named configmap. I think that works as well. I am not sure how a role will work, unless we create one in openshift-config-managed namespace.
|
@gnufied: This pull request references Jira Issue OCPBUGS-18132, which is invalid:
Comment The bug has been updated to refer to the pull request using the external bug tracker. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
|
/jira refresh |
|
@gnufied: This pull request references Jira Issue OCPBUGS-18132, which is valid. 6 validation(s) were run on this bug
DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
|
/lgtm |
|
/label backport-risk-assessed |
|
See test on openshift/vmware-vsphere-csi-driver-operator#169. |
|
/label qe-approved |
|
/cherry-pick release-4.12 |
|
@gnufied: once the present PR merges, I will cherry-pick it on top of release-4.12 in a new PR and assign it to you. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
|
/retest-required |
|
/retest |
|
@gnufied: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here. |
|
@gnufied: Jira Issue OCPBUGS-18132: All pull requests linked via external trackers have merged: Jira Issue OCPBUGS-18132 has been moved to the MODIFIED state. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
|
@gnufied: new pull request created: #402 DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
|
Fix included in accepted release 4.13.0-0.nightly-2023-09-27-193040 |
Goes with openshift/vmware-vsphere-csi-driver-operator#169
Fixes OCPBUGS-18132