Update ClusterRole permissions of messaging topology operator to update secrets #1033
Add this suggestion to a batch that can be applied as a single commit. This suggestion is invalid because no changes were made to the code. Suggestions cannot be applied while the pull request is closed. Suggestions cannot be applied while viewing a subset of changes. Only one suggestion per line can be applied in a batch. Add this suggestion to a batch that can be applied as a single commit. Applying suggestions on deleted lines is not supported. You must change the existing code in this line in order to create a valid suggestion. Outdated suggestions cannot be applied. This suggestion has been applied or marked resolved. Suggestions cannot be applied from pending reviews. Suggestions cannot be applied on multi-line comments. Suggestions cannot be applied while the pull request is queued to merge. Suggestion cannot be applied right now. Please check back later.
This closes #
I had communicated this problem in Discord on 27th Aug
Note to reviewers: remember to look at the commits in this PR and consider if they can be squashed
Note to contributors: remember to re-generate client set if there are any API changes
Summary Of Changes
The manager role currently is missing updating permissions of secrets which leads to some issues in case importCredentials is being used. Therefore the patch and update verbs have been added to the ClusterRole.
Additional Context
When creating a user and loading already existing secrets the manager-operator role will try to update it, it looks like it is adding metadata. Due to missing permissions this will fail with something like:
secrets "<user>-user-credentials" is forbidden: User "system:serviceaccount:<namespace>:messaging-topology-operator" cannot update resource "secrets" in API group "" in the namespace "<namespace>"The ClusterRole rules is missing for
secretsthe verbspatch / updateI found a PR in bitnami helm charts which has dealt with the same problem.