@@ -54,83 +54,82 @@ metadata:
5454 labels :
5555 {{- include "aws-load-balancer-controller.labels" . | nindent 4 }}
5656rules :
57- - apiGroups : ["elbv2.k8s.aws"]
58- resources : [targetgroupbindings]
59- verbs : [create, delete, get, list, patch, update, watch]
60- - apiGroups : ["elbv2.k8s.aws"]
61- resources : [ingressclassparams]
62- verbs : [get, list, watch]
63- - apiGroups : ["elbv2.k8s.aws"]
64- resources : [albtargetcontrolconfigs]
65- verbs : [get]
57+ # AUTO-GENERATED from config/rbac/role.yaml by hack/sync-rbac-to-helm.sh
58+ # Do not edit these rules manually. Run 'make manifests' to update.
6659- apiGroups : [""]
67- resources : [events ]
68- verbs : [create, patch ]
60+ resources : [configmaps ]
61+ verbs : [create, delete, get, update ]
6962- apiGroups : [""]
70- resources : [pods]
71- verbs : [get, list, watch]
72- - apiGroups : ["networking.k8s.io"]
73- resources : [ingressclasses]
63+ resources : [endpoints, namespaces, nodes, pods]
7464 verbs : [get, list, watch]
75- - apiGroups : ["", "extensions", "networking.k8s.io"]
76- resources : [services, ingresses]
77- verbs : [get, list, patch, update, watch]
7865- apiGroups : [""]
79- resources : [nodes, namespaces, endpoints ]
80- verbs : [get, list, watch ]
66+ resources : [events ]
67+ verbs : [create, patch ]
8168- apiGroups : [""]
82- resources : [configmaps]
83- verbs : [get, delete, create, update]
84- {{- if .Values.clusterSecretsPermissions.allowAllSecrets }}
69+ resources : [pods/status, services/status]
70+ verbs : [patch, update]
8571- apiGroups : [""]
86- resources : [secrets]
87- verbs : [get, list, watch]
88- {{- end }}
89- - apiGroups : ["elbv2.k8s.aws", "", "extensions", "networking.k8s.io"]
90- resources : [targetgroupbindings/status, pods/status, services/status, ingresses/status]
91- verbs : [update, patch]
72+ resources : [services]
73+ verbs : [get, list, patch, update, watch]
74+ - apiGroups : ["aga.k8s.aws"]
75+ resources : [globalaccelerators]
76+ verbs : [get, list, patch, watch]
77+ - apiGroups : ["aga.k8s.aws"]
78+ resources : [globalaccelerators/finalizers, globalaccelerators/status]
79+ verbs : [patch, update]
9280- apiGroups : ["discovery.k8s.io"]
9381 resources : [endpointslices]
9482 verbs : [get, list, watch]
83+ - apiGroups : ["elbv2.k8s.aws"]
84+ resources : [albtargetcontrolconfigs]
85+ verbs : [get]
86+ - apiGroups : ["elbv2.k8s.aws"]
87+ resources : [ingressclassparams]
88+ verbs : [get, list, watch]
89+ - apiGroups : ["elbv2.k8s.aws"]
90+ resources : [targetgroupbindings]
91+ verbs : [create, delete, get, list, patch, update, watch]
92+ - apiGroups : ["elbv2.k8s.aws"]
93+ resources : [targetgroupbindings/status]
94+ verbs : [patch, update]
95+ - apiGroups : ["extensions", "networking.k8s.io"]
96+ resources : [ingresses]
97+ verbs : [get, list, patch, update, watch]
98+ - apiGroups : ["extensions", "networking.k8s.io"]
99+ resources : [ingresses/status]
100+ verbs : [patch, update]
95101- apiGroups : ["gateway.k8s.aws"]
96- resources : [loadbalancerconfigurations, targetgroupconfigurations, listenerruleconfigurations ]
97- verbs : [get, list, watch, patch ]
102+ resources : [listenerruleconfigurations, loadbalancerconfigurations, targetgroupconfigurations ]
103+ verbs : [get, list, patch, watch ]
98104- apiGroups : ["gateway.k8s.aws"]
99- resources : [loadbalancerconfigurations /finalizers, targetgroupconfigurations /finalizers, listenerruleconfigurations /finalizers]
100- verbs : [update, patch ]
105+ resources : [listenerruleconfigurations /finalizers, loadbalancerconfigurations /finalizers, targetgroupconfigurations /finalizers]
106+ verbs : [patch, update ]
101107- apiGroups : ["gateway.k8s.aws"]
102- resources : [loadbalancerconfigurations/status, targetgroupconfigurations/status, listenerruleconfigurations/status]
103- verbs : [get, patch, watch]
104- - apiGroups : ["gateway.networking.k8s.io"]
105- resources : [gatewayclasses, gateways]
106- verbs : [get, list, watch, patch]
108+ resources : [listenerruleconfigurations/status, loadbalancerconfigurations/status, targetgroupconfigurations/status]
109+ verbs : [get, patch, update]
107110- apiGroups : ["gateway.networking.k8s.io"]
108- resources : [referencegrants]
109- verbs : [get, list, watch]
111+ resources : [gatewayclasses, gateways, referencegrants]
112+ verbs : [get, list, patch, watch]
110113- apiGroups : ["gateway.networking.k8s.io"]
111114 resources : [gatewayclasses/finalizers, gateways/finalizers]
112- verbs : [update, patch ]
115+ verbs : [patch, update ]
113116- apiGroups : ["gateway.networking.k8s.io"]
114- resources : [gatewayclasses/status, gateways/status]
117+ resources : [gatewayclasses/status, gateways/status, grpcroutes/status, httproutes/status, listenersets/status, tcproutes/status, tlsroutes/status, udproutes/status ]
115118 verbs : [get, patch, update]
116119- apiGroups : ["gateway.networking.k8s.io"]
117- resources : [grpcroutes, httproutes, tcproutes, tlsroutes, udproutes, listenersets ]
120+ resources : [grpcroutes, httproutes, listenersets, tcproutes, tlsroutes, udproutes]
118121 verbs : [get, list, watch]
119122- apiGroups : ["gateway.networking.k8s.io"]
120- resources : [grpcroutes/finalizers, httproutes/finalizers, tcproutes /finalizers, tlsroutes /finalizers, udproutes /finalizers, listenersets /finalizers]
123+ resources : [grpcroutes/finalizers, httproutes/finalizers, listenersets /finalizers, tcproutes /finalizers, tlsroutes /finalizers, udproutes /finalizers]
121124 verbs : [update]
122- - apiGroups : ["gateway.networking.k8s.io"]
123- resources : [grpcroutes/status, httproutes/status, tcproutes/status, tlsroutes/status, udproutes/status, listenersets/status]
124- verbs : [get, patch, update]
125- - apiGroups : ["aga.k8s.aws"]
126- resources : [globalaccelerators]
127- verbs : [get, list, patch, watch]
128- - apiGroups : ["aga.k8s.aws"]
129- resources : [globalaccelerators/finalizers]
130- verbs : [patch, update]
131- - apiGroups : ["aga.k8s.aws"]
132- resources : [globalaccelerators/status]
133- verbs : [patch, update]
125+ - apiGroups : ["networking.k8s.io"]
126+ resources : [ingressclasses]
127+ verbs : [get, list, watch]
128+ {{- if .Values.clusterSecretsPermissions.allowAllSecrets }}
129+ - apiGroups : [""]
130+ resources : [secrets]
131+ verbs : [get, list, watch]
132+ {{- end }}
134133---
135134apiVersion : rbac.authorization.k8s.io/v1
136135kind : ClusterRoleBinding
0 commit comments