kubespray/roles
Frank Ritchie 5b0e88339a
Update cilium-operator clusterrole (#7416)
When upgrading cilium from 1.8.8 to 1.9.5 I ran into the following
error:

level=error msg="Unable to update CRD" error="customresourcedefinitions.apiextensions.k8s.io
\"ciliumnodes.cilium.io\" is forbidden: User \"system:serviceaccount:kube-system:cilium-operator\"
cannot update resource \"customresourcedefinitions\" in API group \"apiextensions.k8s.io\" at the
cluster scope" name=CiliumNode/v2 subsys=k8s

The fix was to add the update verb to the clusterrole. I also added
create to match the clusterrole created by the cilium helm chart.
2021-03-29 00:04:51 -07:00
..
adduser Fix nologin wrong path (#6272) 2020-06-16 02:30:04 -07:00
bastion-ssh-config Allow connecting to bastion via non-standard SSH port (#7396) 2021-03-26 00:48:43 -07:00
bootstrap-os Remove DNSSEC config management in bootstrap-debian.yml (#7408) 2021-03-29 00:00:45 -07:00
container-engine Replace kube-master with kube_control_plane (#7256) 2021-03-23 17:26:05 -07:00
download Set Kube-router version to 1.2.0 (#7402) 2021-03-24 09:22:07 -07:00
etcd Remove vault (#7400) 2021-03-24 09:26:08 -07:00
etcdctl Only use stat get_checksum: yes when needed (#7270) 2021-02-10 05:36:59 -08:00
kubernetes Fix k8s-certs-renew for k8s < 1.20 (#7410) 2021-03-26 08:44:44 -07:00
kubernetes-apps specify runAsGroup, allow safe sysctls by default (#7399) 2021-03-25 08:03:30 -07:00
kubespray-defaults Allow connecting to bastion via non-standard SSH port (#7396) 2021-03-26 00:48:43 -07:00
network_plugin Update cilium-operator clusterrole (#7416) 2021-03-29 00:04:51 -07:00
recover_control_plane Replace kube-master with kube_control_plane (#7256) 2021-03-23 17:26:05 -07:00
remove-node Fix remove-node by removing jq usage (#7405) 2021-03-26 08:48:43 -07:00
reset Remove vault (#7400) 2021-03-24 09:26:08 -07:00
upgrade Replace kube-master with kube_control_plane (#7256) 2021-03-23 17:26:05 -07:00
win_nodes/kubernetes_patch Cleanup old checks for k8s 1.18 (#7192) 2021-01-19 08:43:45 -08:00