Skip to content

Commit

Permalink
Revert "Configure rbac for ui-server ocm-mc mode (#140)"
Browse files Browse the repository at this point in the history
This reverts commit f4d7228.
  • Loading branch information
tamalsaha committed Jan 12, 2024
1 parent f4d7228 commit f30df4d
Show file tree
Hide file tree
Showing 9 changed files with 188 additions and 240 deletions.
14 changes: 0 additions & 14 deletions charts/kube-ui-server/common/cluster-role-binding.yaml

This file was deleted.

52 changes: 0 additions & 52 deletions charts/kube-ui-server/common/cluster-role.yaml

This file was deleted.

116 changes: 0 additions & 116 deletions charts/kube-ui-server/common/user-roles.yaml

This file was deleted.

16 changes: 14 additions & 2 deletions charts/kube-ui-server/templates/k8s/cluster-role-binding.yaml
Original file line number Diff line number Diff line change
@@ -1,6 +1,18 @@
{{- if not .Values.kubeconfigSecretName }}

{{- $restpl := $.Files.Get "common/cluster-role-binding.yaml" -}}
{{ tpl $restpl $ }}
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: {{ include "kube-ui-server.fullname" . }}
labels:
{{- include "kube-ui-server.labels" . | nindent 4 }}
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: {{ include "kube-ui-server.fullname" . }}
subjects:
- kind: ServiceAccount
name: {{ include "kube-ui-server.serviceAccountName" . }}
namespace: {{ .Release.Namespace }}

{{- end }}
54 changes: 52 additions & 2 deletions charts/kube-ui-server/templates/k8s/cluster-role.yaml
Original file line number Diff line number Diff line change
@@ -1,6 +1,56 @@
{{- if not .Values.kubeconfigSecretName }}

{{- $restpl := $.Files.Get "common/cluster-role.yaml" -}}
{{ tpl $restpl $ }}
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: {{ include "kube-ui-server.fullname" . }}
labels:
{{- include "kube-ui-server.labels" . | nindent 4 }}
rules:
- apiGroups:
- core.k8s.appscode.com
- cost.k8s.appscode.com
- identity.k8s.appscode.com
- management.k8s.appscode.com
- meta.k8s.appscode.com
- policy.k8s.appscode.com
- ui.k8s.appscode.com
resources:
- "*"
verbs: ["*"]
- apiGroups:
- source.toolkit.fluxcd.io
resources:
- helmrepositories
verbs: ["get", "list", "watch"]
- apiGroups:
- ""
resources:
- secrets
verbs: ["get", "list", "watch"]
- apiGroups:
- ""
resources:
- configmaps
verbs: ["*"]
- apiGroups:
- ""
resources:
- events
verbs: ["create"]
- apiGroups:
- '*'
resources:
- '*'
verbs:
# create used for raw REST query
- create
- get
- list
- watch
- nonResourceURLs:
- '*'
verbs:
- get

{{- end }}
122 changes: 120 additions & 2 deletions charts/kube-ui-server/templates/k8s/user-roles.yaml
Original file line number Diff line number Diff line change
@@ -1,6 +1,124 @@
{{- if not .Values.kubeconfigSecretName }}

{{- $restpl := $.Files.Get "common/user-roles.yaml" -}}
{{ tpl $restpl $ }}
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: kubeops:ui:editor
labels:
rbac.authorization.k8s.io/aggregate-to-admin: "true"
rbac.authorization.k8s.io/aggregate-to-edit: "true"
annotations:
"helm.sh/hook": post-install,post-upgrade
"helm.sh/hook-delete-policy": before-hook-creation
rules:
- apiGroups:
- core.k8s.appscode.com
- cost.k8s.appscode.com
- identity.k8s.appscode.com
- management.k8s.appscode.com
- meta.k8s.appscode.com
- policy.k8s.appscode.com
- ui.k8s.appscode.com
resources:
- "*"
verbs: ["*"]

---

apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: kubeops:ui:viewer
labels:
rbac.authorization.k8s.io/aggregate-to-view: "true"
annotations:
"helm.sh/hook": post-install,post-upgrade
"helm.sh/hook-delete-policy": before-hook-creation
rules:
- apiGroups:
- auditor.appscode.com
resources:
- siteinfos
verbs: ["create"]
- apiGroups:
- identity.k8s.appscode.com
resources:
- whoamis
verbs: ["create"]
- apiGroups:
- core.k8s.appscode.com
resources:
- genericresources
- genericresourceservices
- podviews
- projects
- resourcesummaries
verbs: ["get", "list"]
- apiGroups:
- management.k8s.appscode.com
resources:
- projectquotas
verbs: ["get", "list"]
- apiGroups:
- ui.k8s.appscode.com
resources:
- features
- featuresets
- resourcedashboards
- resourceeditors
verbs: ["get", "list"]
- apiGroups:
- meta.k8s.appscode.com
resources:
- chartpresetqueries
- clusterstatuses
- renderdashboards
- rendermenus
- renderrawgraphs
- renders
- resourcecalculators
- resourcegraphs
verbs: ["create"]
- apiGroups:
- meta.k8s.appscode.com
resources:
- menus
- resourceblockdefinitions
- resourcedescriptors
- resourcelayouts
- resourceoutlines
- resourcetabledefinitions
- usermenus
verbs: ["get", "list"]
- apiGroups:
- meta.k8s.appscode.com
resources:
- menus/available
- usermenus/available
verbs: ["get"]
- apiGroups:
- meta.k8s.appscode.com
resources:
- usermenus
verbs: ["*"]

---

# required for standard user in Rancher
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: kubeops:ui:viewer
annotations:
"helm.sh/hook": post-install,post-upgrade
"helm.sh/hook-delete-policy": before-hook-creation
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: kubeops:ui:viewer
subjects:
- kind: Group
name: system:authenticated
apiGroup: rbac.authorization.k8s.io

{{- end }}
Loading

0 comments on commit f30df4d

Please sign in to comment.