The platform-engineer ArgoCD account was created (argocd-cm.yaml) with apiKey capability, but no argocd-rbac-cm ConfigMap existed, so the account had default (empty) RBAC and every API call returned 403. This adds the RBAC policy granting the platform-engineer role: - get applications (all projects/namespaces) - sync applications (all projects/namespaces) - get projects Needed for the platform-engineer cron jobs to read app health and trigger syncs via the ArgoCD API.
16 lines
445 B
YAML
16 lines
445 B
YAML
apiVersion: v1
|
|
kind: ConfigMap
|
|
metadata:
|
|
name: argocd-rbac-cm
|
|
namespace: argocd
|
|
labels:
|
|
app.kubernetes.io/name: argocd-rbac-cm
|
|
app.kubernetes.io/part-of: argocd
|
|
data:
|
|
policy.default: ""
|
|
policy.csv: |
|
|
p, role:platform-engineer, applications, get, */*, allow
|
|
p, role:platform-engineer, applications, sync, */*, allow
|
|
p, role:platform-engineer, projects, get, *, allow
|
|
g, platform-engineer, role:platform-engineer
|