Files
k3s-cluster/argocd/argocd-rbac-cm.yaml
platform-engineer c971647734 fix(argocd): add argocd-rbac-cm granting platform-engineer read+sync on applications
The platform-engineer ArgoCD local account had apiKey+login capabilities
but no RBAC role assignment. With no argocd-rbac-cm ConfigMap in the repo,
the default policy gave the account zero permissions, so every API call
to list applications returned an empty list — the watchdog could not see
any apps to check their health.

This adds an argocd-rbac-cm ConfigMap with a role:platform-engineer that
has get (read) and sync on all applications in all projects, and assigns
the platform-engineer account to that role.
2026-07-06 13:06:51 +00:00

16 lines
476 B
YAML

apiVersion: v1
kind: ConfigMap
metadata:
name: argocd-rbac-cm
namespace: argocd
labels:
app.kubernetes.io/name: argocd-rbac-cm
app.kubernetes.io/part-of: argocd
data:
policy.csv: |
# Grant the platform-engineer local account read + sync access to all applications
p, role:platform-engineer, applications, get, */*, allow
p, role:platform-engineer, application, sync, */*, allow
g, platform-engineer, role:platform-engineer
policy.default: ""