fix: Remove inert subjectaccessreviews and reorganize RBAC rules - #6736
Conversation
f413d82 to
d29cb50
Compare
|
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #6736 +/- ##
=======================================
Coverage 46.82% 46.82%
=======================================
Files 415 415
Lines 50406 50406
Branches 7215 7215
=======================================
Hits 23601 23601
Misses 25155 25155
Partials 1650 1650
Continue to review full report in Codecov by Harness.
🚀 New features to boost your workflow:
|
9054385 to
b93fe1b
Compare
Signed-off-by: ntkathole <nikhilkathole2683@gmail.com>
b93fe1b to
7577f6b
Compare
HaoXuAI
left a comment
There was a problem hiding this comment.
The RBAC split matches the controller's actual CreateOrUpdate and cleanup operations, and removing the inert subjectaccessreviews rules is correct. No blocking findings from my review.
Summary
Remove the unused subjectaccessreviews from the operator ClusterRole and reorganize the RBAC rules for clusterrolebindings and clusterroles to follow the principle of least privilege.
Changes
Test Plan