From 601c40b1d8843a461fed3e3a2e9297c653bc972b Mon Sep 17 00:00:00 2001 From: Dmytro Alieksieiev <1865999+dragoangel@users.noreply.github.com> Date: Thu, 22 Aug 2024 18:50:15 +0200 Subject: [PATCH] helm: Always add nodes read permissions to provisioner ClusterRole Signed-off-by: Dmytro Alieksieiev <1865999+dragoangel@users.noreply.github.com> --- charts/ceph-csi-rbd/templates/provisioner-clusterrole.yaml | 2 -- 1 file changed, 2 deletions(-) diff --git a/charts/ceph-csi-rbd/templates/provisioner-clusterrole.yaml b/charts/ceph-csi-rbd/templates/provisioner-clusterrole.yaml index ad79fd707..b2c01ae62 100644 --- a/charts/ceph-csi-rbd/templates/provisioner-clusterrole.yaml +++ b/charts/ceph-csi-rbd/templates/provisioner-clusterrole.yaml @@ -81,14 +81,12 @@ rules: resources: ["persistentvolumeclaims/status"] verbs: ["update", "patch"] {{- end }} -{{- if .Values.topology.domainLabels }} - apiGroups: [""] resources: ["nodes"] verbs: ["get", "list","watch"] - apiGroups: ["storage.k8s.io"] resources: ["csinodes"] verbs: ["get", "list", "watch"] -{{- end }} - apiGroups: [""] resources: ["serviceaccounts/token"] verbs: ["create"]