Skip to content

Commit 7d21ad2

Browse files
committed
restrict permissions for clusterrole and clusterrolebinding to specific resources
Signed-off-by: lokielse <[email protected]>
1 parent 6519029 commit 7d21ad2

File tree

1 file changed

+22
-1
lines changed

1 file changed

+22
-1
lines changed

deployments/gpu-operator/templates/clusterrole.yaml

Lines changed: 22 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -43,12 +43,33 @@ rules:
4343
- clusterrolebindings
4444
verbs:
4545
- create
46-
- get
4746
- list
4847
- watch
48+
- apiGroups:
49+
- rbac.authorization.k8s.io
50+
resources:
51+
- clusterroles
52+
- clusterrolebindings
53+
verbs:
54+
- get
4955
- update
5056
- patch
5157
- delete
58+
resourceNames:
59+
- nvidia-cc-manager
60+
- nvidia-device-plugin
61+
- nvidia-device-plugin-mps-control-daemon
62+
- nvidia-driver
63+
- nvidia-gpu-feature-discovery
64+
- nvidia-kata-manager
65+
- nvidia-mig-manager
66+
- nvidia-node-status-exporter
67+
- nvidia-operator-validator
68+
- nvidia-sandbox-device-plugin
69+
- nvidia-sandbox-validator
70+
- nvidia-vfio-manager
71+
- nvidia-vgpu-device-manager
72+
- nvidia-vgpu-manager
5273
- apiGroups:
5374
- ""
5475
resources:

0 commit comments

Comments
 (0)