diff --git a/README.md b/README.md index 8c864bf..8ae93b4 100644 --- a/README.md +++ b/README.md @@ -26,6 +26,14 @@ helm upgrade --install odigos odigos/odigos --namespace odigos-system --create-n kubectl label namespace odigos-system odigos.io/system-object="true" ``` +### Managing SCCs in OpenShift for Odigos + +```console +oc adm policy add-scc-to-group anyuid system:serviceaccounts:odigos-system +oc adm policy add-scc-to-user privileged -z odiglet -n odigos-system +oc adm policy add-scc-to-user privileged -z odigos-data-collection -n odigos-system +``` + ### Upgrade Existing Odigos Installation ```console diff --git a/charts/odigos/templates/autoscaler/clusterrole.yaml b/charts/odigos/templates/autoscaler/clusterrole.yaml index c4c924e..f9dfdd9 100644 --- a/charts/odigos/templates/autoscaler/clusterrole.yaml +++ b/charts/odigos/templates/autoscaler/clusterrole.yaml @@ -4,35 +4,29 @@ metadata: name: odigos-autoscaler rules: - apiGroups: - - odigos.io + - "" resources: - - instrumentedapplications + - configmaps + - services verbs: - - create - - delete - get - list - - patch - - update - watch - apiGroups: - - odigos.io - resources: - - instrumentedapplications/finalizers - verbs: - - update - - apiGroups: - - odigos.io + - apps resources: - - instrumentedapplications/status + - daemonsets + - deployments verbs: - get - - patch - - update + - list + - watch - apiGroups: - odigos.io resources: + - instrumentedapplications - collectorsgroups + - odigosconfigurations - destinations - processors verbs: @@ -47,6 +41,7 @@ rules: - odigos.io resources: - collectorsgroups/finalizers + - instrumentedapplications/finalizers - destinations/finalizers verbs: - update @@ -54,6 +49,7 @@ rules: - odigos.io resources: - collectorsgroups/status + - instrumentedapplications/status - destinations/status verbs: - get @@ -104,4 +100,4 @@ rules: verbs: - get - list - - watch \ No newline at end of file + - watch diff --git a/charts/odigos/templates/odiglet/clusterrole.yaml b/charts/odigos/templates/odiglet/clusterrole.yaml index 91cf4de..195524d 100644 --- a/charts/odigos/templates/odiglet/clusterrole.yaml +++ b/charts/odigos/templates/odiglet/clusterrole.yaml @@ -32,6 +32,14 @@ rules: - get - list - watch + - apiGroups: + - apps + resources: + - daemonsets/finalizers + - deployments/finalizers + - statefulsets/finalizers + verbs: + - update - apiGroups: - apps resources: