c12s-kubespray/roles/network_plugin/cilium/templates
Frank Ritchie 5b0e88339a
Update cilium-operator clusterrole (#7416)
When upgrading cilium from 1.8.8 to 1.9.5 I ran into the following
error:

level=error msg="Unable to update CRD" error="customresourcedefinitions.apiextensions.k8s.io
\"ciliumnodes.cilium.io\" is forbidden: User \"system:serviceaccount:kube-system:cilium-operator\"
cannot update resource \"customresourcedefinitions\" in API group \"apiextensions.k8s.io\" at the
cluster scope" name=CiliumNode/v2 subsys=k8s

The fix was to add the update verb to the clusterrole. I also added
create to match the clusterrole created by the cilium helm chart.
2021-03-29 00:04:51 -07:00
..
000-cilium-portmap.conflist.j2 Upgrade Cilium network plugin to v1.5.5. (#5014) 2019-08-06 01:37:55 -07:00
cilium-config.yml.j2 Add support for cilium ipsec (#7342) 2021-03-23 13:46:06 -07:00
cilium-cr.yml.j2 Update cilium-operator clusterrole (#7416) 2021-03-29 00:04:51 -07:00
cilium-crb.yml.j2 Remove executable bit from yaml and j2 files (#6894) 2020-11-29 20:18:48 -08:00
cilium-deploy.yml.j2 Update Cilium to 1.8.3 (#6629) 2020-09-07 02:11:49 -07:00
cilium-ds.yml.j2 Add support for cilium ipsec (#7342) 2021-03-23 13:46:06 -07:00
cilium-sa.yml.j2 Remove executable bit from yaml and j2 files (#6894) 2020-11-29 20:18:48 -08:00
cilium-secret.yml.j2 Add support for cilium ipsec (#7342) 2021-03-23 13:46:06 -07:00