VPA: Update vpa-rbac.yaml for allowing in place resize requests

Signed-off-by: Max Cao <macao@redhat.com>
This commit is contained in:
Max Cao 2025-03-24 10:50:57 -07:00
parent d6376c48f6
commit 15883dce79
No known key found for this signature in database
GPG Key ID: 4EAEC3318EC211D2
1 changed files with 26 additions and 0 deletions

View File

@ -124,6 +124,32 @@ rules:
- create
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: system:vpa-updater-in-place
rules:
- apiGroups:
- ""
resources:
- pods/resize
- pods # required for patching vpaInPlaceUpdated annotations onto the pod
verbs:
- patch
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: system:vpa-updater-in-place-binding
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: system:vpa-updater-in-place
subjects:
- kind: ServiceAccount
name: vpa-updater
namespace: kube-system
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: system:metrics-reader