diff --git a/cluster-scope/overlays/nerc-ocp-test/kustomization.yaml b/cluster-scope/overlays/nerc-ocp-test/kustomization.yaml index 3a65d943..334fa7e2 100644 --- a/cluster-scope/overlays/nerc-ocp-test/kustomization.yaml +++ b/cluster-scope/overlays/nerc-ocp-test/kustomization.yaml @@ -17,6 +17,7 @@ resources: - nodenetworkconfigurationpolicies - feature/odf - feature/rhoai +- rbac - ../../bundles/clusterissuer-http01 - ../../bundles/gatekeeper-operator - ../../bundles/hostpath-provisioner @@ -73,6 +74,7 @@ patches: - ocp-on-nerc/nerc-ops - ocp-on-nerc/nerc-logs-metrics - ocp-on-nerc/nerc-rhods + - ocp-on-nerc/nerc-test-people - target: kind: ExternalSecret name: github-client-secret diff --git a/cluster-scope/overlays/nerc-ocp-test/rbac/kustomization.yaml b/cluster-scope/overlays/nerc-ocp-test/rbac/kustomization.yaml new file mode 100644 index 00000000..8dfbd31a --- /dev/null +++ b/cluster-scope/overlays/nerc-ocp-test/rbac/kustomization.yaml @@ -0,0 +1,4 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +resources: +- nerc-test-people.yaml diff --git a/cluster-scope/overlays/nerc-ocp-test/rbac/nerc-test-people.yaml b/cluster-scope/overlays/nerc-ocp-test/rbac/nerc-test-people.yaml new file mode 100644 index 00000000..18e89128 --- /dev/null +++ b/cluster-scope/overlays/nerc-ocp-test/rbac/nerc-test-people.yaml @@ -0,0 +1,12 @@ +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: nerc-test-people-readers +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: cluster-reader +subjects: +- apiGroup: rbac.authorization.k8s.io + kind: Group + name: nerc-test-people