Skip to content

Add RBAC roles for ESO#55

Closed
pinikomarov wants to merge 1 commit into
openstack-k8s-operators:mainfrom
pinikomarov:eso_rbac
Closed

Add RBAC roles for ESO#55
pinikomarov wants to merge 1 commit into
openstack-k8s-operators:mainfrom
pinikomarov:eso_rbac

Conversation

@pinikomarov

@pinikomarov pinikomarov commented Jun 14, 2026

Copy link
Copy Markdown
Contributor

@pinikomarov pinikomarov force-pushed the eso_rbac branch 7 times, most recently from 5219efe to ce2c846 Compare June 15, 2026 19:41
@pinikomarov pinikomarov marked this pull request as ready for review June 16, 2026 04:05
@pinikomarov pinikomarov requested a review from cjeanner June 16, 2026 08:02
@pinikomarov pinikomarov self-assigned this Jun 16, 2026
@pinikomarov

Copy link
Copy Markdown
Contributor Author

Tested to work on e2e deployment here:
https://gitlab.cee.redhat.com/pkomarov/examples/-/pipelines/15970042

metadata:
name: cluster
annotations:
argocd.argoproj.io/sync-wave: "1"

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

that should be added to the sync-wave component.

@@ -0,0 +1,28 @@
---
# Allow ESO pods to reach Vault (vault.corp.redhat.com:8200).

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

publishing an internal name on public repository?

# Allow ESO pods to reach Vault (vault.corp.redhat.com:8200).
# The RHESO operator creates a deny-all-traffic NetworkPolicy by default,
# so egress to Vault must be explicitly permitted.
# Using corporate network CIDR (10.30.0.0/16) instead of specific IP

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

publishing internal range?

@cjeanner cjeanner closed this Jun 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants