diff --git a/apps/base/cephrgw-system/deployment.yaml b/apps/base/cephrgw-system/deployment.yaml index 2e005fe..93a543f 100644 --- a/apps/base/cephrgw-system/deployment.yaml +++ b/apps/base/cephrgw-system/deployment.yaml @@ -24,7 +24,7 @@ spec: runAsNonRoot: true containers: - name: operator - image: git.unkin.net/unkin/cephrgw-operator:v0.3.0 + image: git.unkin.net/unkin/cephrgw-operator:v0.3.1 args: - --metrics-bind-address=:8080 - --health-probe-bind-address=:8081 diff --git a/apps/base/cephrgw-system/kustomization.yaml b/apps/base/cephrgw-system/kustomization.yaml index 6df7822..388fe1d 100644 --- a/apps/base/cephrgw-system/kustomization.yaml +++ b/apps/base/cephrgw-system/kustomization.yaml @@ -6,7 +6,7 @@ resources: - namespace.yaml # CRDs are pulled from the cephrgw-operator repo at the matching tag rather # than vendored here, so they never drift from the operator. - - https://git.unkin.net/unkin/cephrgw-operator/raw/tag/v0.3.0/config/crd/install.yaml + - https://git.unkin.net/unkin/cephrgw-operator/raw/tag/v0.3.1/config/crd/install.yaml - rbac.yaml - deployment.yaml - vaultauth.yaml diff --git a/apps/base/cephrgw-system/rbac.yaml b/apps/base/cephrgw-system/rbac.yaml index aad1349..aabefcc 100644 --- a/apps/base/cephrgw-system/rbac.yaml +++ b/apps/base/cephrgw-system/rbac.yaml @@ -23,6 +23,10 @@ rules: - apiGroups: ["coordination.k8s.io"] resources: ["leases"] verbs: ["get", "list", "watch", "create", "update", "patch", "delete"] + # v0.3.1 startup check reads its own CRDs to warn if they are stale/missing. + - apiGroups: ["apiextensions.k8s.io"] + resources: ["customresourcedefinitions"] + verbs: ["get", "list"] --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding