fix(argocd): add argocd-rbac-cm granting platform-engineer read+sync on applications
The platform-engineer ArgoCD local account had apiKey+login capabilities but no RBAC role assignment. With no argocd-rbac-cm ConfigMap in the repo, the default policy gave the account zero permissions, so every API call to list applications returned an empty list — the watchdog could not see any apps to check their health. This adds an argocd-rbac-cm ConfigMap with a role:platform-engineer that has get (read) and sync on all applications in all projects, and assigns the platform-engineer account to that role.
This commit is contained in:
15
argocd/argocd-rbac-cm.yaml
Normal file
15
argocd/argocd-rbac-cm.yaml
Normal file
@@ -0,0 +1,15 @@
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: argocd-rbac-cm
|
||||
namespace: argocd
|
||||
labels:
|
||||
app.kubernetes.io/name: argocd-rbac-cm
|
||||
app.kubernetes.io/part-of: argocd
|
||||
data:
|
||||
policy.csv: |
|
||||
# Grant the platform-engineer local account read + sync access to all applications
|
||||
p, role:platform-engineer, applications, get, */*, allow
|
||||
p, role:platform-engineer, application, sync, */*, allow
|
||||
g, platform-engineer, role:platform-engineer
|
||||
policy.default: ""
|
||||
Reference in New Issue
Block a user