ichp-project-editor.yaml 8.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606
  1. aggregationRule:
  2. clusterRoleSelectors:
  3. - matchLabels:
  4. rbac.ichp.ing.net/aggregate-to-ichp-project-admin: "true"
  5. apiVersion: rbac.authorization.k8s.io/v1
  6. kind: ClusterRole
  7. metadata:
  8. annotations:
  9. kubectl.kubernetes.io/last-applied-configuration: |
  10. {"aggregationRule":{"clusterRoleSelectors":[{"matchLabels":{"rbac.ichp.ing.net/aggregate-to-ichp-project-admin":"true"}}]},"apiVersion":"rbac.authorization.k8s.io/v1","kind":"ClusterRole","metadata":{"annotations":{},"labels":{"app.kubernetes.io/instance":"rbac","app.kubernetes.io/managed-by":"Helms","app.kubernetes.io/name":"ichp-rbac","app.kubernetes.io/version":"1.16.0","helm.sh/chart":"ichp-rbac-0.1.0"},"name":"ichp-project-editor"}}
  11. creationTimestamp: "2024-03-08T22:14:44Z"
  12. labels:
  13. app.kubernetes.io/instance: rbac
  14. app.kubernetes.io/managed-by: Helms
  15. app.kubernetes.io/name: ichp-rbac
  16. app.kubernetes.io/version: 1.16.0
  17. helm.sh/chart: ichp-rbac-0.1.0
  18. name: ichp-project-editor
  19. resourceVersion: "116612"
  20. uid: c1d134ae-f610-4b9b-b552-cdd58a52f363
  21. rules:
  22. - apiGroups:
  23. - authdelegation.ichp.ing.net
  24. resources:
  25. - authdelegations
  26. verbs:
  27. - '*'
  28. - apiGroups:
  29. - cert-manager.io
  30. resources:
  31. - certificaterequests
  32. - certificaterequests/status
  33. - certificates
  34. - certificates/status
  35. - issuers
  36. - issuers/status
  37. verbs:
  38. - create
  39. - delete
  40. - get
  41. - list
  42. - patch
  43. - update
  44. - watch
  45. - apiGroups:
  46. - acme.cert-manager.io
  47. resources:
  48. - challenges
  49. - challenges/status
  50. - orders
  51. - orders/status
  52. verbs:
  53. - create
  54. - delete
  55. - get
  56. - list
  57. - patch
  58. - update
  59. - watch
  60. - apiGroups:
  61. - operators.coreos.com
  62. resources:
  63. - catalogsources
  64. - clusterserviceversions
  65. - installplans
  66. - subscriptions
  67. verbs:
  68. - create
  69. - delete
  70. - get
  71. - list
  72. - patch
  73. - update
  74. - watch
  75. - apiGroups:
  76. - monitoring.coreos.com
  77. resources:
  78. - alertmanagers
  79. verbs:
  80. - create
  81. - delete
  82. - patch
  83. - update
  84. - get
  85. - list
  86. - watch
  87. - apiGroups:
  88. - monitoring.coreos.com
  89. resources:
  90. - prometheuses
  91. verbs:
  92. - create
  93. - delete
  94. - patch
  95. - update
  96. - get
  97. - list
  98. - watch
  99. - apiGroups:
  100. - monitoring.coreos.com
  101. resources:
  102. - prometheusrules
  103. verbs:
  104. - create
  105. - delete
  106. - patch
  107. - update
  108. - get
  109. - list
  110. - watch
  111. - apiGroups:
  112. - monitoring.coreos.com
  113. resources:
  114. - servicemonitors
  115. verbs:
  116. - create
  117. - delete
  118. - patch
  119. - update
  120. - get
  121. - list
  122. - watch
  123. - apiGroups:
  124. - ""
  125. resources:
  126. - configmaps
  127. - endpoints
  128. - limitranges
  129. - persistentvolumeclaims
  130. - pods
  131. - replicationcontrollers
  132. - replicationcontrollers/scale
  133. - secrets
  134. - serviceaccounts
  135. - services
  136. - services/proxy
  137. verbs:
  138. - create
  139. - delete
  140. - deletecollection
  141. - get
  142. - list
  143. - patch
  144. - update
  145. - watch
  146. - apiGroups:
  147. - ""
  148. resources:
  149. - bindings
  150. - events
  151. - namespaces/status
  152. - pods/log
  153. - pods/status
  154. - replicationcontrollers/status
  155. - resourcequotas
  156. - resourcequotas/status
  157. verbs:
  158. - get
  159. - list
  160. - watch
  161. - apiGroups:
  162. - ""
  163. resources:
  164. - namespaces
  165. verbs:
  166. - get
  167. - list
  168. - watch
  169. - apiGroups:
  170. - ""
  171. resources:
  172. - serviceaccounts
  173. verbs:
  174. - impersonate
  175. - apiGroups:
  176. - apps
  177. resources:
  178. - daemonsets
  179. - deployments
  180. - deployments/rollback
  181. - deployments/scale
  182. - replicasets
  183. - replicasets/scale
  184. - statefulsets
  185. - statefulsets/scale
  186. verbs:
  187. - create
  188. - delete
  189. - deletecollection
  190. - get
  191. - list
  192. - patch
  193. - update
  194. - watch
  195. - apiGroups:
  196. - autoscaling
  197. resources:
  198. - horizontalpodautoscalers
  199. verbs:
  200. - create
  201. - delete
  202. - deletecollection
  203. - get
  204. - list
  205. - patch
  206. - update
  207. - watch
  208. - apiGroups:
  209. - batch
  210. resources:
  211. - cronjobs
  212. - jobs
  213. verbs:
  214. - create
  215. - delete
  216. - deletecollection
  217. - get
  218. - list
  219. - patch
  220. - update
  221. - watch
  222. - apiGroups:
  223. - extensions
  224. resources:
  225. - daemonsets
  226. - deployments
  227. - deployments/rollback
  228. - deployments/scale
  229. - ingresses
  230. - networkpolicies
  231. - replicasets
  232. - replicasets/scale
  233. - replicationcontrollers/scale
  234. verbs:
  235. - create
  236. - delete
  237. - deletecollection
  238. - get
  239. - list
  240. - patch
  241. - update
  242. - watch
  243. - apiGroups:
  244. - policy
  245. resources:
  246. - poddisruptionbudgets
  247. verbs:
  248. - create
  249. - delete
  250. - deletecollection
  251. - get
  252. - list
  253. - patch
  254. - update
  255. - watch
  256. - apiGroups:
  257. - networking.k8s.io
  258. resources:
  259. - networkpolicies
  260. verbs:
  261. - create
  262. - delete
  263. - deletecollection
  264. - get
  265. - list
  266. - patch
  267. - update
  268. - watch
  269. - apiGroups:
  270. - authorization.k8s.io
  271. resources:
  272. - localsubjectaccessreviews
  273. verbs:
  274. - create
  275. - apiGroups:
  276. - rbac.authorization.k8s.io
  277. resources:
  278. - rolebindings
  279. - roles
  280. verbs:
  281. - bind
  282. - create
  283. - delete
  284. - deletecollection
  285. - get
  286. - list
  287. - patch
  288. - update
  289. - watch
  290. - apiGroups:
  291. - ""
  292. - authorization.openshift.io
  293. resources:
  294. - rolebindings
  295. - roles
  296. verbs:
  297. - bind
  298. - create
  299. - delete
  300. - deletecollection
  301. - get
  302. - list
  303. - patch
  304. - update
  305. - watch
  306. - apiGroups:
  307. - ""
  308. - authorization.openshift.io
  309. resources:
  310. - localresourceaccessreviews
  311. - localsubjectaccessreviews
  312. - subjectrulesreviews
  313. verbs:
  314. - create
  315. - apiGroups:
  316. - ""
  317. - security.openshift.io
  318. resources:
  319. - podsecuritypolicyreviews
  320. - podsecuritypolicyselfsubjectreviews
  321. - podsecuritypolicysubjectreviews
  322. verbs:
  323. - create
  324. - apiGroups:
  325. - ""
  326. - authorization.openshift.io
  327. resources:
  328. - rolebindingrestrictions
  329. verbs:
  330. - get
  331. - list
  332. - watch
  333. - apiGroups:
  334. - ""
  335. - build.openshift.io
  336. resources:
  337. - buildconfigs
  338. - buildconfigs/webhooks
  339. - builds
  340. verbs:
  341. - create
  342. - delete
  343. - deletecollection
  344. - get
  345. - list
  346. - patch
  347. - update
  348. - watch
  349. - apiGroups:
  350. - ""
  351. - build.openshift.io
  352. resources:
  353. - builds/log
  354. verbs:
  355. - get
  356. - list
  357. - watch
  358. - apiGroups:
  359. - ""
  360. - build.openshift.io
  361. resources:
  362. - buildconfigs/instantiate
  363. - buildconfigs/instantiatebinary
  364. - builds/clone
  365. verbs:
  366. - create
  367. - apiGroups:
  368. - ""
  369. - build.openshift.io
  370. resources:
  371. - builds/details
  372. verbs:
  373. - update
  374. - apiGroups:
  375. - build.openshift.io
  376. resources:
  377. - jenkins
  378. verbs:
  379. - admin
  380. - edit
  381. - view
  382. - apiGroups:
  383. - ""
  384. - apps.openshift.io
  385. resources:
  386. - deploymentconfigs
  387. - deploymentconfigs/scale
  388. verbs:
  389. - create
  390. - delete
  391. - deletecollection
  392. - get
  393. - list
  394. - patch
  395. - update
  396. - watch
  397. - apiGroups:
  398. - ""
  399. - apps.openshift.io
  400. resources:
  401. - deploymentconfigrollbacks
  402. - deploymentconfigs/instantiate
  403. - deploymentconfigs/rollback
  404. verbs:
  405. - create
  406. - apiGroups:
  407. - ""
  408. - apps.openshift.io
  409. resources:
  410. - deploymentconfigs/log
  411. - deploymentconfigs/status
  412. verbs:
  413. - get
  414. - list
  415. - watch
  416. - apiGroups:
  417. - ""
  418. - image.openshift.io
  419. resources:
  420. - imagestreamimages
  421. - imagestreammappings
  422. - imagestreams
  423. - imagestreams/secrets
  424. - imagestreamtags
  425. verbs:
  426. - create
  427. - delete
  428. - deletecollection
  429. - get
  430. - list
  431. - patch
  432. - update
  433. - watch
  434. - apiGroups:
  435. - ""
  436. - image.openshift.io
  437. resources:
  438. - imagestreams/status
  439. verbs:
  440. - get
  441. - list
  442. - watch
  443. - apiGroups:
  444. - ""
  445. - image.openshift.io
  446. resources:
  447. - imagestreams/layers
  448. verbs:
  449. - get
  450. - update
  451. - apiGroups:
  452. - ""
  453. - image.openshift.io
  454. resources:
  455. - imagestreamimports
  456. verbs:
  457. - create
  458. - apiGroups:
  459. - ""
  460. - project.openshift.io
  461. resources:
  462. - projects
  463. verbs:
  464. - delete
  465. - get
  466. - patch
  467. - update
  468. - apiGroups:
  469. - ""
  470. - quota.openshift.io
  471. resources:
  472. - appliedclusterresourcequotas
  473. verbs:
  474. - get
  475. - list
  476. - watch
  477. - apiGroups:
  478. - ""
  479. - route.openshift.io
  480. resources:
  481. - routes
  482. verbs:
  483. - create
  484. - delete
  485. - deletecollection
  486. - get
  487. - list
  488. - patch
  489. - update
  490. - watch
  491. - apiGroups:
  492. - ""
  493. - route.openshift.io
  494. resources:
  495. - routes/custom-host
  496. verbs:
  497. - create
  498. - apiGroups:
  499. - ""
  500. - route.openshift.io
  501. resources:
  502. - routes/status
  503. verbs:
  504. - get
  505. - list
  506. - watch
  507. - apiGroups:
  508. - ""
  509. - route.openshift.io
  510. resources:
  511. - routes/status
  512. verbs:
  513. - update
  514. - apiGroups:
  515. - ""
  516. - template.openshift.io
  517. resources:
  518. - processedtemplates
  519. - templateconfigs
  520. - templateinstances
  521. - templates
  522. verbs:
  523. - create
  524. - delete
  525. - deletecollection
  526. - get
  527. - list
  528. - patch
  529. - update
  530. - watch
  531. - apiGroups:
  532. - extensions
  533. - networking.k8s.io
  534. resources:
  535. - networkpolicies
  536. verbs:
  537. - create
  538. - delete
  539. - deletecollection
  540. - get
  541. - list
  542. - patch
  543. - update
  544. - watch
  545. - apiGroups:
  546. - ""
  547. - build.openshift.io
  548. resources:
  549. - buildlogs
  550. verbs:
  551. - create
  552. - delete
  553. - deletecollection
  554. - get
  555. - list
  556. - patch
  557. - update
  558. - watch
  559. - apiGroups:
  560. - ""
  561. resources:
  562. - resourcequotausages
  563. verbs:
  564. - get
  565. - list
  566. - watch
  567. - apiGroups:
  568. - ""
  569. - authorization.openshift.io
  570. resources:
  571. - resourceaccessreviews
  572. - subjectaccessreviews
  573. verbs:
  574. - create
  575. - apiGroups:
  576. - metrics.k8s.io
  577. resources:
  578. - pods
  579. verbs:
  580. - get
  581. - list
  582. - apiGroups:
  583. - networking.k8s.io
  584. resources:
  585. - ingresses
  586. verbs:
  587. - create
  588. - delete
  589. - deletecollection
  590. - get
  591. - list
  592. - patch
  593. - update
  594. - watch
  595. - apiGroups:
  596. - ichp.ing.net
  597. resources:
  598. - quotaautoscalers
  599. verbs:
  600. - create
  601. - delete
  602. - get
  603. - list
  604. - patch
  605. - update
  606. - watch