Skip to content

Commit

Permalink
Remove list permission for secrets:
Browse files Browse the repository at this point in the history
This is unneeded and a potential security risk.

Signed-off-by: Jacob Weinstock <[email protected]>
  • Loading branch information
jacobweinstock committed Jun 4, 2024
1 parent 81557c0 commit 36b127c
Show file tree
Hide file tree
Showing 2 changed files with 1 addition and 2 deletions.
1 change: 0 additions & 1 deletion config/rbac/role.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,6 @@ rules:
- secrets
verbs:
- get
- list
- watch
- apiGroups:
- bmc.tinkerbell.org
Expand Down
2 changes: 1 addition & 1 deletion controller/machine.go
Original file line number Diff line number Diff line change
Expand Up @@ -60,7 +60,7 @@ func NewMachineReconciler(c client.Client, recorder record.EventRecorder, bmcCli
//+kubebuilder:rbac:groups=bmc.tinkerbell.org,resources=machines,verbs=get;list;watch;create;update;patch;delete
//+kubebuilder:rbac:groups=bmc.tinkerbell.org,resources=machines/status,verbs=get;update;patch
//+kubebuilder:rbac:groups=bmc.tinkerbell.org,resources=machines/finalizers,verbs=update
//+kubebuilder:rbac:groups="",resources=secrets;,verbs=get;list;watch
//+kubebuilder:rbac:groups="",resources=secrets;,verbs=get;watch

// Reconcile reports on the state of a Machine. It does not change the state of the Machine in any way.
// Updates the Power status and conditions accordingly.
Expand Down

0 comments on commit 36b127c

Please sign in to comment.