Browse Source

Merge pull request #6536 from shawn-hurley/adding-asb-permissions

Adding ability for ASB to interact with network resources.
Scott Dodson 7 years ago
parent
commit
df19291645
1 changed files with 9 additions and 0 deletions
  1. 9 0
      roles/ansible_service_broker/tasks/install.yml

+ 9 - 0
roles/ansible_service_broker/tasks/install.yml

@@ -72,6 +72,15 @@
       - apiGroups: ["image.openshift.io", ""]
         resources: ["images"]
         verbs: ["get", "list"]
+      - apiGroups: ["network.openshift.io"]
+        resources: ["clusternetworks", "netnamespaces"]
+        verbs: ["get"]
+      - apiGroups: ["network.openshift.io"]
+        resources: ["netnamespaces"]
+        verbs: ["update"]
+      - apiGroups: ["networking.k8s.io"]
+        resources: ["networkpolicies"]
+        verbs: ["create", "delete"]
 
 - name: Create asb-access cluster role
   oc_clusterrole: