Skip to content

Conversation

Wieneo
Copy link
Contributor

@Wieneo Wieneo commented Jun 5, 2025

Description

This PR fixes a problem with the RBAC permission that occurs if the runtime cluster is also a seed.
In this scenario, two managed resources fight over the ClusterRole and ClusterRoleBinding.

This PR adds separate RBAC permissions with different naming for the runtime deployment.
(This is in-line with other extensions -> see https://github.com/gardener/gardener-extension-provider-gcp/blob/master/charts/gardener-extension-provider-gcp/templates/rbac-runtime.yaml)

@Wieneo Wieneo requested a review from a team as a code owner June 5, 2025 13:28
@robertvolkmann robertvolkmann requested a review from Gerrit91 June 5, 2025 14:26
@github-project-automation github-project-automation bot moved this to Review in Development Jun 5, 2025
@Gerrit91 Gerrit91 removed the status in Development Jun 13, 2025
Copy link
Collaborator

@robertvolkmann robertvolkmann left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good. Could you run make generate to generate a new controller-registration.yaml?

@github-project-automation github-project-automation bot moved this to In Progress in Development Jul 2, 2025
@Wieneo
Copy link
Contributor Author

Wieneo commented Jul 2, 2025

@robertvolkmann did :)

@robertvolkmann robertvolkmann merged commit d4dc24d into metal-stack:main Jul 2, 2025
1 of 3 checks passed
@github-project-automation github-project-automation bot moved this from In Progress to Done in Development Jul 2, 2025
@robertvolkmann
Copy link
Collaborator

@Wieneo released.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Archived in project
Development

Successfully merging this pull request may close these issues.

2 participants