This repository was archived by the owner on Sep 9, 2026. It is now read-only.
Add secrets RBAC to hub-access Role - #45
Merged
openshift-merge-bot[bot] merged 1 commit intoFeb 26, 2026
Merged
openshift-merge-bot[bot] merged 1 commit into
openshift-merge-bot[bot] merged 1 commit into
Conversation
tzvatot
force-pushed
the
feature/hub-access-secrets-rbac-mgmt-23103
branch
from
February 26, 2026 12:51
81da855 to
01ed322
Compare
adriengentil
approved these changes
Feb 26, 2026
The fulfillment-service requires permissions to manage Kubernetes Secrets in the hub namespace to support the userDataSecretRef field, which stores cloud-init user data as a Secret rather than requiring users to create it manually. Related: https://issues.redhat.com/browse/MGMT-23103 Generated with [Claude Code](https://claude.com/claude-code)
tzvatot
force-pushed
the
feature/hub-access-secrets-rbac-mgmt-23103
branch
from
February 26, 2026 13:04
01ed322 to
c30894c
Compare
adriengentil
approved these changes
Feb 26, 2026
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: adriengentil, tzvatot The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
3 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
secretscreatepermission to thehub-accessRoleuserDataSecretReffeature: the fulfillment-service creates a Kubernetes Secret in the hub namespace to store cloud-init user data provided via the APIcreateis needed — the Secret uses owner references to the ComputeInstance CR for automatic cleanup, and the user data field is immutable so no update is requiredRelated