-
Notifications
You must be signed in to change notification settings - Fork 779
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Helm chart parameters to tune sdk RBAC #438
Comments
You can create your own service account for the SDK pod: Long term, we may manually only apply this just the sidecar, see #150 for some more details (or remove it from the GameServer process) There could be possible options to manually mount secrets into your containers to allow a specific service account as well, if you want to go that experimental route. Does that solve your problem? |
|
I'm not sure how we can provide values in values.yaml to extend something as complicated as RBAC permissions. Suggestions would be appreciated! (or PRs!) @Kuqd - do you have any ideas I'm almost wondering if it's better if you update the RBAC permissions yourself after you install the helm chart.
This would need to be done at the install time - we couldn't do this at runtime in the CRD. But a |
OK |
Now: I tune helm chart install\helm\agones\templates\serviceaccounts\sdk.yaml to enable communicate between my sidecar and k8s, due this ClusterRole applied to all containers in mutation hook:
Proposal: allow additional tunes in helm or allow manual accounts tune for containers in gs
The text was updated successfully, but these errors were encountered: