diff --git a/examples/full-cluster/cluster-roles/deployer-clusterrole.tf b/examples/full-cluster/cluster-roles/deployer-clusterrole.tf index 0ca031a..7cede6e 100644 --- a/examples/full-cluster/cluster-roles/deployer-clusterrole.tf +++ b/examples/full-cluster/cluster-roles/deployer-clusterrole.tf @@ -6,7 +6,6 @@ resource "kubernetes_cluster_role" "cicd_deployer_istiosystem_cluster_role" { rule { api_groups = ["acme.cert-manager.io"] resources = ["challenges", "orders", "certificaterequests"] - verbs = ["create", "delete", "deletecollection", "get", "list", "patch", "update", "patch"] } @@ -19,7 +18,6 @@ resource "kubernetes_cluster_role" "cicd_deployer_istiosystem_cluster_role" { rule { verbs = ["create", "delete", "deletecollection", "get", "list", "patch", "update", "patch"] - api_groups = ["networking.istio.io"] resources = ["gateways"] } @@ -65,4 +63,5 @@ resource "kubernetes_cluster_role" "cicd_deployer_application_cluster_role" { resources = ["certificates"] verbs = ["create", "delete", "deletecollection", "get", "list", "patch", "update", "patch"] } + } diff --git a/examples/full-cluster/cluster-roles/deployer.iam.tf b/examples/full-cluster/cluster-roles/deployer.iam.tf index 1b22261..13f4192 100644 --- a/examples/full-cluster/cluster-roles/deployer.iam.tf +++ b/examples/full-cluster/cluster-roles/deployer.iam.tf @@ -1,6 +1,6 @@ locals { policy_cicd_k8s_group_name = replace(local.cicd_k8s_iam_username, local._prefixes["eks-user"], local._prefixes["eks-policy"]) - role_cicd_k8s_group_name = replace(local.cicd_k8s_iam_username, local._prefixes["eks-user"],"") + role_cicd_k8s_group_name = replace(local.cicd_k8s_iam_username, local._prefixes["eks-user"], "") iam_policies_cicd = ["p-inf-manage-access-keys"] } @@ -66,7 +66,7 @@ locals { resources = ["*"] } ECRWrite = { -# effect = "Deny" + # effect = "Deny" actions = [ "ecr:BatchDeleteImage", "ecr:CompleteLayerUpload", diff --git a/examples/full-cluster/cluster-roles/variables.tf b/examples/full-cluster/cluster-roles/variables.tf index b11041c..2a571bf 100644 --- a/examples/full-cluster/cluster-roles/variables.tf +++ b/examples/full-cluster/cluster-roles/variables.tf @@ -30,7 +30,7 @@ variable "cicd_k8s_user_name" { variable "cicd_k8s_group_name" { description = "The Group name of CICD Deployer belongs to (excluding prefix for service account and cluster)" type = string - default = "cicd-deployer" + default = "cicd-deployer" } variable "dba_k8s_user_name" { @@ -41,7 +41,7 @@ variable "dba_k8s_user_name" { variable "dba_k8s_group_name" { description = "The Group name of dba-admin belongs to (excluding prefix for service account and cluster)" type = string - default = "dba-admin" + default = "dba-admin" } variable "deployer_application_rolebinding_name" {