Skip to content

Commit 311094f

Browse files
authored
fix(RHOAIENG-34218): Trusty AI Grants All Authenticated users to list pods in any namespace (#587)
Currently the non admin role and clusterrolebinding allows pods and pvcs in any namespace to be viewed by any authenticated user, breaking multi-tenancy. This commit removes just those permissions.
1 parent 8cd2115 commit 311094f

File tree

1 file changed

+0
-16
lines changed

1 file changed

+0
-16
lines changed

config/rbac/non_admin_lmeval_role.yaml

Lines changed: 0 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -28,19 +28,3 @@ rules:
2828
- lmevaljobs/status
2929
verbs:
3030
- get
31-
- apiGroups:
32-
- ""
33-
resources:
34-
- pods
35-
verbs:
36-
- get
37-
- list
38-
- watch
39-
- apiGroups:
40-
- ""
41-
resources:
42-
- persistentvolumeclaims
43-
verbs:
44-
- get
45-
- list
46-
- watch

0 commit comments

Comments
 (0)