Skip to content

Commit 97d7684

Browse files
aliokjaideepr97mikebrow
authored
Manual cherry pick PR#73 to release-0.1 branch (#78)
* add aggregation labels to clustrroles Signed-off-by: Jaideep Rao <jrao@redhat.com> (cherry picked from commit e3696a2) * Update config/rbac/mcpserver_admin_role.yaml Co-authored-by: Mike Brown <brownwm@us.ibm.com> (cherry picked from commit 1d35aec) * Update config/rbac/mcpserver_editor_role.yaml Co-authored-by: Mike Brown <brownwm@us.ibm.com> (cherry picked from commit 38b611f) * Update config/rbac/mcpserver_viewer_role.yaml Co-authored-by: Mike Brown <brownwm@us.ibm.com> (cherry picked from commit 16d76b8) --------- Signed-off-by: Jaideep Rao <jrao@redhat.com> Co-authored-by: Jaideep Rao <jrao@redhat.com> Co-authored-by: Jaideep Rao <jaideep.r97@gmail.com> Co-authored-by: Mike Brown <brownwm@us.ibm.com>
1 parent 1c39a19 commit 97d7684

3 files changed

Lines changed: 6 additions & 0 deletions

File tree

config/rbac/mcpserver_admin_role.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,8 @@ metadata:
1414
labels:
1515
app.kubernetes.io/name: mcp-lifecycle-operator
1616
app.kubernetes.io/managed-by: kustomize
17+
# Add these permissions to the "admin" default role.
18+
rbac.authorization.k8s.io/aggregate-to-admin: "true"
1719
name: mcpserver-admin-role
1820
rules:
1921
- apiGroups:

config/rbac/mcpserver_editor_role.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,8 @@ metadata:
1414
labels:
1515
app.kubernetes.io/name: mcp-lifecycle-operator
1616
app.kubernetes.io/managed-by: kustomize
17+
# Add these permissions to the "edit" default role.
18+
rbac.authorization.k8s.io/aggregate-to-edit: "true"
1719
name: mcpserver-editor-role
1820
rules:
1921
- apiGroups:

config/rbac/mcpserver_viewer_role.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,8 @@ metadata:
1414
labels:
1515
app.kubernetes.io/name: mcp-lifecycle-operator
1616
app.kubernetes.io/managed-by: kustomize
17+
# Add these permissions to the "view" default role.
18+
rbac.authorization.k8s.io/aggregate-to-view: "true"
1719
name: mcpserver-viewer-role
1820
rules:
1921
- apiGroups:

0 commit comments

Comments
 (0)