mirror of
https://github.com/kubernetes-sigs/kubespray.git
synced 2025-12-13 21:34:40 +03:00
Update Calico apiserver RBAC for Kubernetes 1.33+ (#12654)
Add missing RBAC permissions for Calico apiserver to function correctly with Kubernetes 1.33+ Changes: 1. Add K8s 1.33 ValidatingAdmissionPolicy resources to calico-webhook-reader - validatingadmissionpolicies - validatingadmissionpolicybindings Kubernetes 1.33 introduced ValidatingAdmissionPolicy resources (KEP-3488) that require explicit RBAC permissions. Without these changes, Calico apiserver on k8s 1.33+ will not work and needless errors are logged
This commit is contained in:
@@ -235,6 +235,8 @@ rules:
|
||||
resources:
|
||||
- mutatingwebhookconfigurations
|
||||
- validatingwebhookconfigurations
|
||||
- validatingadmissionpolicies # Required for Kubernetes 1.33+
|
||||
- validatingadmissionpolicybindings # Required for Kubernetes 1.33+
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
|
||||
Reference in New Issue
Block a user