diff --git a/config/rbac/role.yaml b/config/rbac/role.yaml index 62bee5f7..6d43ff41 100644 --- a/config/rbac/role.yaml +++ b/config/rbac/role.yaml @@ -130,7 +130,7 @@ rules: - apiGroups: - batch resourceNames: - - '["eventing-manager-cert-handler"]' + - eventing-manager-cert-handler resources: - cronjobs verbs: @@ -138,7 +138,7 @@ rules: - apiGroups: - batch resourceNames: - - '["eventing-manager-cert-handler"]' + - eventing-manager-cert-handler resources: - jobs verbs: diff --git a/internal/controller/operator/eventing/controller.go b/internal/controller/operator/eventing/controller.go index 0484fb19..361a77ef 100644 --- a/internal/controller/operator/eventing/controller.go +++ b/internal/controller/operator/eventing/controller.go @@ -172,8 +172,8 @@ func NewReconciler( // +kubebuilder:rbac:groups="eventing.kyma-project.io",resources=subscriptions,verbs=get;list;watch;update;patch;create;delete // +kubebuilder:rbac:groups=eventing.kyma-project.io,resources=subscriptions/status,verbs=get;update;patch // +kubebuilder:rbac:groups=security.istio.io,resources=peerauthentications,verbs=get;list;watch;create;update;patch;delete -// +kubebuilder:rbac:groups="batch",resources=jobs,verbs=delete,resourceNames=["eventing-manager-cert-handler"] -// +kubebuilder:rbac:groups="batch",resources=cronjobs,verbs=delete,resourceNames=["eventing-manager-cert-handler"] +// +kubebuilder:rbac:groups="batch",resources=jobs,verbs=delete,resourceNames={"eventing-manager-cert-handler"} +// +kubebuilder:rbac:groups="batch",resources=cronjobs,verbs=delete,resourceNames={"eventing-manager-cert-handler"} // Generate required RBAC to emit kubernetes events in the controller. // +kubebuilder:rbac:groups="",resources=events,verbs=create;patch