Files
cluster-state/infrastructure/argocd/argocd-rbac.yaml
2026-06-03 22:07:07 +02:00

25 lines
745 B
YAML

apiVersion: v1
kind: ConfigMap
metadata:
name: argocd-rbac-cm
namespace: argocd
labels:
app.kubernetes.io/name: argocd-rbac-cm
app.kubernetes.io/part-of: argocd
data:
# Unangemeldete / unbekannte User haben keinen Zugriff
policy.default: role:''
policy.csv: |
# readonly: darf alles sehen, nichts ändern
p, role:readonly, applications, get, */*, allow
p, role:readonly, projects, get, *, allow
p, role:readonly, repositories, get, *, allow
p, role:readonly, clusters, get, *, allow
p, role:readonly, logs, get, */*, allow
g, ntiebor, role:readonly
p, ntiebor, applications, *, default/root-apps, allow
g, prejuge, role:readonly
p, prejuge, applications, *, default/root-apps, allow