Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

inquiry regarding RBAC permission on service account: clickhouse-operator #646

Closed
leoxhj opened this issue Feb 4, 2021 · 2 comments
Closed
Labels
in testing work in progress This feautre is not completed yet

Comments

@leoxhj
Copy link

leoxhj commented Feb 4, 2021

Dear team,

we noticed the rbac for clickhouse-operator is binding to highest cluster role user: cluster-admin, this is not allowed for our production environment since we need to specify detail cluster resources and give out as minimum permission as possible to prevent security issues, would you kindly please advice on those specific resouces permission for the sa? e.g. pvc, pod, ...

Thanks.

@sunsingerus
Copy link
Collaborator

clickhouse-operator role is restricted with PR #675
PR is merged into 0.14.0 branch
Feel free to provide any feedback

@sunsingerus sunsingerus added in testing work in progress This feautre is not completed yet labels Apr 15, 2021
@alex-zaitsev
Copy link
Member

Fixed in https://github.com/Altinity/clickhouse-operator/releases/tag/0.14.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
in testing work in progress This feautre is not completed yet
Projects
None yet
Development

No branches or pull requests

3 participants