diff --git a/charts/operator-wandb/charts/console/templates/clusterrole.yaml b/charts/operator-wandb/charts/console/templates/clusterrole.yaml index 4094e728..79035ea6 100644 --- a/charts/operator-wandb/charts/console/templates/clusterrole.yaml +++ b/charts/operator-wandb/charts/console/templates/clusterrole.yaml @@ -16,14 +16,17 @@ metadata: {{- toYaml .Values.clusterRole.annotations | nindent 4 }} {{- end }} rules: - # We can scope these permissions down later - # - apiGroups: ["*"] - # resources: ["*"] - # verbs: ["*"] - - apiGroups: [""] - resources: ["secrets"] - verbs: ["get", "create", "update", "delete"] - - apiGroups: [""] - resources: ["namespaces"] - verbs: ["get"] +rules: +- apiGroups: [""] + resources: ["secrets"] + verbs: ["get", "list", "watch", "patch"] +- apiGroups: [""] + resources: ["nodes", "namespaces", "pods", "pods/log", "configmaps", "services", "serviceaccounts", "events"] + verbs: ["get", "list"] +- apiGroups: ["apps"] + resources: ["deployments", "statefulsets", "daemonsets", "replicasets", "controllerrevisions"] + verbs: ["get", "list"] +- apiGroups: ["apps"] + resources: ["deployments/status", "statefulsets/status", "daemonsets/status", "replicasets/status"] + verbs: ["get"] {{- end }} \ No newline at end of file