Files
sbbb/base/vso/test-rbac.yaml
Sienna Meridian Satterwhite 3ecb42056f chore: replace sunbeam.py with cli package; fix VSO test RBAC
Remove scripts/sunbeam.py — superseded by the new cli/ package.
Add install/test/sunbeam targets to justfile pointing at ../cli/.

fix(vso): add deletecollection to test-rbac Role — CachingClientFactory
calls deletecollection on secrets during init; the old Role only had
delete, causing vault-secrets-operator-test to CrashLoopBackOff.

fix(ingress): pingora imagePullPolicy IfNotPresent — Always caused
unnecessary pulls on every pod restart in local dev.
2026-03-02 21:01:03 +00:00

31 lines
971 B
YAML

---
# Grant the default SA in vault-secrets-operator the permissions the Helm
# test pod needs. The test runs the VSO binary which initializes its Vault
# client cache by creating/reading a K8s Secret in this namespace.
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: vault-secrets-operator-test
namespace: vault-secrets-operator
rules:
- apiGroups: [""]
resources: ["secrets", "configmaps"]
verbs: ["create", "get", "update", "delete", "deletecollection", "list", "watch"]
- apiGroups: ["coordination.k8s.io"]
resources: ["leases"]
verbs: ["create", "get", "update", "delete", "list", "watch"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: vault-secrets-operator-test
namespace: vault-secrets-operator
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: vault-secrets-operator-test
subjects:
- kind: ServiceAccount
name: default
namespace: vault-secrets-operator