ichp-project-admin.yaml 9.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607
  1. aggregationRule:
  2. clusterRoleSelectors:
  3. - matchLabels:
  4. rbac.ichp.ing.net/aggregate-to-ichp-project-admin: "true"
  5. apiVersion: rbac.authorization.k8s.io/v1
  6. kind: ClusterRole
  7. metadata:
  8. annotations:
  9. argocd.argoproj.io/sync-options: Prune=false
  10. kubectl.kubernetes.io/last-applied-configuration: |
  11. {"aggregationRule":{"clusterRoleSelectors":[{"matchLabels":{"rbac.ichp.ing.net/aggregate-to-ichp-project-admin":"true"}}]},"apiVersion":"rbac.authorization.k8s.io/v1","kind":"ClusterRole","metadata":{"annotations":{"argocd.argoproj.io/sync-options":"Prune=false"},"labels":{"app.kubernetes.io/instance":"rbac","app.kubernetes.io/managed-by":"Helms","app.kubernetes.io/name":"ichp-rbac","app.kubernetes.io/version":"1.16.0","helm.sh/chart":"ichp-rbac-0.1.0"},"name":"ichp-project-admin"}}
  12. creationTimestamp: "2024-03-08T22:14:44Z"
  13. labels:
  14. app.kubernetes.io/instance: rbac
  15. app.kubernetes.io/managed-by: Helms
  16. app.kubernetes.io/name: ichp-rbac
  17. app.kubernetes.io/version: 1.16.0
  18. helm.sh/chart: ichp-rbac-0.1.0
  19. name: ichp-project-admin
  20. resourceVersion: "116608"
  21. uid: 48e3d4b3-e8ef-41bf-9edf-020a8a88f14c
  22. rules:
  23. - apiGroups:
  24. - authdelegation.ichp.ing.net
  25. resources:
  26. - authdelegations
  27. verbs:
  28. - '*'
  29. - apiGroups:
  30. - cert-manager.io
  31. resources:
  32. - certificaterequests
  33. - certificaterequests/status
  34. - certificates
  35. - certificates/status
  36. - issuers
  37. - issuers/status
  38. verbs:
  39. - create
  40. - delete
  41. - get
  42. - list
  43. - patch
  44. - update
  45. - watch
  46. - apiGroups:
  47. - acme.cert-manager.io
  48. resources:
  49. - challenges
  50. - challenges/status
  51. - orders
  52. - orders/status
  53. verbs:
  54. - create
  55. - delete
  56. - get
  57. - list
  58. - patch
  59. - update
  60. - watch
  61. - apiGroups:
  62. - operators.coreos.com
  63. resources:
  64. - catalogsources
  65. - clusterserviceversions
  66. - installplans
  67. - subscriptions
  68. verbs:
  69. - create
  70. - delete
  71. - get
  72. - list
  73. - patch
  74. - update
  75. - watch
  76. - apiGroups:
  77. - monitoring.coreos.com
  78. resources:
  79. - alertmanagers
  80. verbs:
  81. - create
  82. - delete
  83. - patch
  84. - update
  85. - get
  86. - list
  87. - watch
  88. - apiGroups:
  89. - monitoring.coreos.com
  90. resources:
  91. - prometheuses
  92. verbs:
  93. - create
  94. - delete
  95. - patch
  96. - update
  97. - get
  98. - list
  99. - watch
  100. - apiGroups:
  101. - monitoring.coreos.com
  102. resources:
  103. - prometheusrules
  104. verbs:
  105. - create
  106. - delete
  107. - patch
  108. - update
  109. - get
  110. - list
  111. - watch
  112. - apiGroups:
  113. - monitoring.coreos.com
  114. resources:
  115. - servicemonitors
  116. verbs:
  117. - create
  118. - delete
  119. - patch
  120. - update
  121. - get
  122. - list
  123. - watch
  124. - apiGroups:
  125. - ""
  126. resources:
  127. - configmaps
  128. - endpoints
  129. - limitranges
  130. - persistentvolumeclaims
  131. - pods
  132. - replicationcontrollers
  133. - replicationcontrollers/scale
  134. - secrets
  135. - serviceaccounts
  136. - services
  137. - services/proxy
  138. verbs:
  139. - create
  140. - delete
  141. - deletecollection
  142. - get
  143. - list
  144. - patch
  145. - update
  146. - watch
  147. - apiGroups:
  148. - ""
  149. resources:
  150. - bindings
  151. - events
  152. - namespaces/status
  153. - pods/log
  154. - pods/status
  155. - replicationcontrollers/status
  156. - resourcequotas
  157. - resourcequotas/status
  158. verbs:
  159. - get
  160. - list
  161. - watch
  162. - apiGroups:
  163. - ""
  164. resources:
  165. - namespaces
  166. verbs:
  167. - get
  168. - list
  169. - watch
  170. - apiGroups:
  171. - ""
  172. resources:
  173. - serviceaccounts
  174. verbs:
  175. - impersonate
  176. - apiGroups:
  177. - apps
  178. resources:
  179. - daemonsets
  180. - deployments
  181. - deployments/rollback
  182. - deployments/scale
  183. - replicasets
  184. - replicasets/scale
  185. - statefulsets
  186. - statefulsets/scale
  187. verbs:
  188. - create
  189. - delete
  190. - deletecollection
  191. - get
  192. - list
  193. - patch
  194. - update
  195. - watch
  196. - apiGroups:
  197. - autoscaling
  198. resources:
  199. - horizontalpodautoscalers
  200. verbs:
  201. - create
  202. - delete
  203. - deletecollection
  204. - get
  205. - list
  206. - patch
  207. - update
  208. - watch
  209. - apiGroups:
  210. - batch
  211. resources:
  212. - cronjobs
  213. - jobs
  214. verbs:
  215. - create
  216. - delete
  217. - deletecollection
  218. - get
  219. - list
  220. - patch
  221. - update
  222. - watch
  223. - apiGroups:
  224. - extensions
  225. resources:
  226. - daemonsets
  227. - deployments
  228. - deployments/rollback
  229. - deployments/scale
  230. - ingresses
  231. - networkpolicies
  232. - replicasets
  233. - replicasets/scale
  234. - replicationcontrollers/scale
  235. verbs:
  236. - create
  237. - delete
  238. - deletecollection
  239. - get
  240. - list
  241. - patch
  242. - update
  243. - watch
  244. - apiGroups:
  245. - policy
  246. resources:
  247. - poddisruptionbudgets
  248. verbs:
  249. - create
  250. - delete
  251. - deletecollection
  252. - get
  253. - list
  254. - patch
  255. - update
  256. - watch
  257. - apiGroups:
  258. - networking.k8s.io
  259. resources:
  260. - networkpolicies
  261. verbs:
  262. - create
  263. - delete
  264. - deletecollection
  265. - get
  266. - list
  267. - patch
  268. - update
  269. - watch
  270. - apiGroups:
  271. - authorization.k8s.io
  272. resources:
  273. - localsubjectaccessreviews
  274. verbs:
  275. - create
  276. - apiGroups:
  277. - rbac.authorization.k8s.io
  278. resources:
  279. - rolebindings
  280. - roles
  281. verbs:
  282. - bind
  283. - create
  284. - delete
  285. - deletecollection
  286. - get
  287. - list
  288. - patch
  289. - update
  290. - watch
  291. - apiGroups:
  292. - ""
  293. - authorization.openshift.io
  294. resources:
  295. - rolebindings
  296. - roles
  297. verbs:
  298. - bind
  299. - create
  300. - delete
  301. - deletecollection
  302. - get
  303. - list
  304. - patch
  305. - update
  306. - watch
  307. - apiGroups:
  308. - ""
  309. - authorization.openshift.io
  310. resources:
  311. - localresourceaccessreviews
  312. - localsubjectaccessreviews
  313. - subjectrulesreviews
  314. verbs:
  315. - create
  316. - apiGroups:
  317. - ""
  318. - security.openshift.io
  319. resources:
  320. - podsecuritypolicyreviews
  321. - podsecuritypolicyselfsubjectreviews
  322. - podsecuritypolicysubjectreviews
  323. verbs:
  324. - create
  325. - apiGroups:
  326. - ""
  327. - authorization.openshift.io
  328. resources:
  329. - rolebindingrestrictions
  330. verbs:
  331. - get
  332. - list
  333. - watch
  334. - apiGroups:
  335. - ""
  336. - build.openshift.io
  337. resources:
  338. - buildconfigs
  339. - buildconfigs/webhooks
  340. - builds
  341. verbs:
  342. - create
  343. - delete
  344. - deletecollection
  345. - get
  346. - list
  347. - patch
  348. - update
  349. - watch
  350. - apiGroups:
  351. - ""
  352. - build.openshift.io
  353. resources:
  354. - builds/log
  355. verbs:
  356. - get
  357. - list
  358. - watch
  359. - apiGroups:
  360. - ""
  361. - build.openshift.io
  362. resources:
  363. - buildconfigs/instantiate
  364. - buildconfigs/instantiatebinary
  365. - builds/clone
  366. verbs:
  367. - create
  368. - apiGroups:
  369. - ""
  370. - build.openshift.io
  371. resources:
  372. - builds/details
  373. verbs:
  374. - update
  375. - apiGroups:
  376. - build.openshift.io
  377. resources:
  378. - jenkins
  379. verbs:
  380. - admin
  381. - edit
  382. - view
  383. - apiGroups:
  384. - ""
  385. - apps.openshift.io
  386. resources:
  387. - deploymentconfigs
  388. - deploymentconfigs/scale
  389. verbs:
  390. - create
  391. - delete
  392. - deletecollection
  393. - get
  394. - list
  395. - patch
  396. - update
  397. - watch
  398. - apiGroups:
  399. - ""
  400. - apps.openshift.io
  401. resources:
  402. - deploymentconfigrollbacks
  403. - deploymentconfigs/instantiate
  404. - deploymentconfigs/rollback
  405. verbs:
  406. - create
  407. - apiGroups:
  408. - ""
  409. - apps.openshift.io
  410. resources:
  411. - deploymentconfigs/log
  412. - deploymentconfigs/status
  413. verbs:
  414. - get
  415. - list
  416. - watch
  417. - apiGroups:
  418. - ""
  419. - image.openshift.io
  420. resources:
  421. - imagestreamimages
  422. - imagestreammappings
  423. - imagestreams
  424. - imagestreams/secrets
  425. - imagestreamtags
  426. verbs:
  427. - create
  428. - delete
  429. - deletecollection
  430. - get
  431. - list
  432. - patch
  433. - update
  434. - watch
  435. - apiGroups:
  436. - ""
  437. - image.openshift.io
  438. resources:
  439. - imagestreams/status
  440. verbs:
  441. - get
  442. - list
  443. - watch
  444. - apiGroups:
  445. - ""
  446. - image.openshift.io
  447. resources:
  448. - imagestreams/layers
  449. verbs:
  450. - get
  451. - update
  452. - apiGroups:
  453. - ""
  454. - image.openshift.io
  455. resources:
  456. - imagestreamimports
  457. verbs:
  458. - create
  459. - apiGroups:
  460. - ""
  461. - project.openshift.io
  462. resources:
  463. - projects
  464. verbs:
  465. - delete
  466. - get
  467. - patch
  468. - update
  469. - apiGroups:
  470. - ""
  471. - quota.openshift.io
  472. resources:
  473. - appliedclusterresourcequotas
  474. verbs:
  475. - get
  476. - list
  477. - watch
  478. - apiGroups:
  479. - ""
  480. - route.openshift.io
  481. resources:
  482. - routes
  483. verbs:
  484. - create
  485. - delete
  486. - deletecollection
  487. - get
  488. - list
  489. - patch
  490. - update
  491. - watch
  492. - apiGroups:
  493. - ""
  494. - route.openshift.io
  495. resources:
  496. - routes/custom-host
  497. verbs:
  498. - create
  499. - apiGroups:
  500. - ""
  501. - route.openshift.io
  502. resources:
  503. - routes/status
  504. verbs:
  505. - get
  506. - list
  507. - watch
  508. - apiGroups:
  509. - ""
  510. - route.openshift.io
  511. resources:
  512. - routes/status
  513. verbs:
  514. - update
  515. - apiGroups:
  516. - ""
  517. - template.openshift.io
  518. resources:
  519. - processedtemplates
  520. - templateconfigs
  521. - templateinstances
  522. - templates
  523. verbs:
  524. - create
  525. - delete
  526. - deletecollection
  527. - get
  528. - list
  529. - patch
  530. - update
  531. - watch
  532. - apiGroups:
  533. - extensions
  534. - networking.k8s.io
  535. resources:
  536. - networkpolicies
  537. verbs:
  538. - create
  539. - delete
  540. - deletecollection
  541. - get
  542. - list
  543. - patch
  544. - update
  545. - watch
  546. - apiGroups:
  547. - ""
  548. - build.openshift.io
  549. resources:
  550. - buildlogs
  551. verbs:
  552. - create
  553. - delete
  554. - deletecollection
  555. - get
  556. - list
  557. - patch
  558. - update
  559. - watch
  560. - apiGroups:
  561. - ""
  562. resources:
  563. - resourcequotausages
  564. verbs:
  565. - get
  566. - list
  567. - watch
  568. - apiGroups:
  569. - ""
  570. - authorization.openshift.io
  571. resources:
  572. - resourceaccessreviews
  573. - subjectaccessreviews
  574. verbs:
  575. - create
  576. - apiGroups:
  577. - metrics.k8s.io
  578. resources:
  579. - pods
  580. verbs:
  581. - get
  582. - list
  583. - apiGroups:
  584. - networking.k8s.io
  585. resources:
  586. - ingresses
  587. verbs:
  588. - create
  589. - delete
  590. - deletecollection
  591. - get
  592. - list
  593. - patch
  594. - update
  595. - watch
  596. - apiGroups:
  597. - ichp.ing.net
  598. resources:
  599. - quotaautoscalers
  600. verbs:
  601. - create
  602. - delete
  603. - get
  604. - list
  605. - patch
  606. - update
  607. - watch