From d45bacb34b03d5521e629c93b19b1f0860cbe7b1 Mon Sep 17 00:00:00 2001 From: Humble Chirammal Date: Tue, 12 Apr 2022 17:06:24 +0530 Subject: [PATCH] rbac: remove unwanted RBAC for endpoint leader election Signed-off-by: Humble Chirammal --- .../csi-snapshotter/rbac-external-provisioner.yaml | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) diff --git a/deploy/kubernetes/csi-snapshotter/rbac-external-provisioner.yaml b/deploy/kubernetes/csi-snapshotter/rbac-external-provisioner.yaml index e140ce26..9051ae3c 100644 --- a/deploy/kubernetes/csi-snapshotter/rbac-external-provisioner.yaml +++ b/deploy/kubernetes/csi-snapshotter/rbac-external-provisioner.yaml @@ -68,7 +68,7 @@ roleRef: apiGroup: rbac.authorization.k8s.io --- -# Provisioner must be able to work with endpoints and leases in current namespace +# Provisioner must be able to work with leases in current namespace # if (and only if) leadership election is enabled kind: Role apiVersion: rbac.authorization.k8s.io/v1 @@ -77,9 +77,6 @@ metadata: namespace: default name: external-provisioner-cfg rules: -- apiGroups: [""] - resources: ["endpoints"] - verbs: ["get", "watch", "list", "delete", "update", "create"] - apiGroups: ["coordination.k8s.io"] resources: ["leases"] verbs: ["get", "watch", "list", "delete", "update", "create"]