mirror of
https://github.com/bvanroll/cicdTest.git
synced 2025-08-29 12:02:47 +00:00
github event listener service account role permissions :/
This commit is contained in:
@@ -47,6 +47,38 @@ spec:
|
|||||||
resourceRef:
|
resourceRef:
|
||||||
name: git-experimental
|
name: git-experimental
|
||||||
---
|
---
|
||||||
|
kind: Role
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
metadata:
|
||||||
|
name: tekton-trigger-role
|
||||||
|
namespace: tekton-pipeline-istio-project-1
|
||||||
|
rules:
|
||||||
|
# Permissions for every EventListener deployment to function
|
||||||
|
- apiGroups: ["tekton.dev"]
|
||||||
|
resources: ["eventlisteners", "triggerbindings", "triggertemplates"]
|
||||||
|
verbs: ["get"]
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources: ["configmaps", "secrets"] # secrets are only needed for Github/Gitlab interceptors
|
||||||
|
verbs: ["get", "list", "watch"]
|
||||||
|
# Permissions to create resources in associated TriggerTemplates
|
||||||
|
- apiGroups: ["tekton.dev"]
|
||||||
|
resources: ["pipelineruns", "pipelineresources", "taskruns"]
|
||||||
|
verbs: ["create"]
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1beta1
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
metadata:
|
||||||
|
name: tekton-trigger-role-binding
|
||||||
|
namespace: tekton-pipeline-istio-project-1
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: tekton-trigger-role
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: service-acc
|
||||||
|
namespace: tekton-pipeline-istio-project-1
|
||||||
|
---
|
||||||
apiVersion: tekton.dev/v1alpha1
|
apiVersion: tekton.dev/v1alpha1
|
||||||
kind: EventListener
|
kind: EventListener
|
||||||
metadata:
|
metadata:
|
||||||
|
Reference in New Issue
Block a user