allow approve certificates that are signed by grpc (#1225)

Signed-off-by: Wei Liu <liuweixa@redhat.com>
This commit is contained in:
Wei Liu
2025-10-27 21:11:45 +08:00
committed by GitHub
parent cc7a3b7b82
commit 678de2604d

View File

@@ -134,8 +134,9 @@ rules:
verbs: ["update", "patch"]
{{end}}
{{if .GRPCAuthEnabled}}
# Allow hub to approve/sign certificates that are signed by grpc
- apiGroups: ["certificates.k8s.io"]
resources: ["signers"]
resourceNames: ["open-cluster-management.io/grpc"]
verbs: ["sign"]
verbs: ["approve", "sign"]
{{end}}