Skip to content

Commit 2fc74dd

Browse files
committed
Update Calico apiserver RBAC for Kubernetes 1.33+
Add missing RBAC permissions for Calico apiserver to function correctly with Kubernetes 1.33+ Changes: 1. Add K8s 1.33 ValidatingAdmissionPolicy resources to calico-webhook-reader - validatingadmissionpolicies - validatingadmissionpolicybindings Kubernetes 1.33 introduced ValidatingAdmissionPolicy resources (KEP-3488) that require explicit RBAC permissions. Without these changes, Calico apiserver on k8s 1.33+ will not work and needless errors are logged
1 parent 5dce75d commit 2fc74dd

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

roles/network_plugin/calico/templates/calico-apiserver.yml.j2

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -235,6 +235,8 @@ rules:
235235
resources:
236236
- mutatingwebhookconfigurations
237237
- validatingwebhookconfigurations
238+
- validatingadmissionpolicies # Required for Kubernetes 1.33+
239+
- validatingadmissionpolicybindings # Required for Kubernetes 1.33+
238240
verbs:
239241
- get
240242
- list

0 commit comments

Comments
 (0)