From b9a33375a8cc179f302440229790ca0b7e75130d Mon Sep 17 00:00:00 2001 From: marcopiraccini Date: Fri, 10 Jul 2026 14:24:59 +0200 Subject: [PATCH 1/2] RBAC to machinist to create K8s secrets Signed-off-by: marcopiraccini --- chart/templates/serviceaccount.yaml | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/chart/templates/serviceaccount.yaml b/chart/templates/serviceaccount.yaml index 7b4f606..80ee5a8 100644 --- a/chart/templates/serviceaccount.yaml +++ b/chart/templates/serviceaccount.yaml @@ -144,6 +144,17 @@ rules: - create - update - patch + # Image-pull secrets: the deploy API creates a dockerconfigjson Secret from the + # registry credentials in the request so a private image can be pulled. Applied + # via server-side apply, so only create + patch are needed -- never get (which + # would expose secret contents) or update/delete. + - apiGroups: + - "" + resources: + - secrets + verbs: + - create + - patch {{- end }} # Gateway API - for skew protection (opt-in) - apiGroups: From 984035a09902051d86ddce05a00e95b4f1b41cc5 Mon Sep 17 00:00:00 2001 From: marcopiraccini Date: Fri, 10 Jul 2026 15:30:40 +0200 Subject: [PATCH 2/2] RBAC to machinist to create K8s secrets Signed-off-by: marcopiraccini --- chart/templates/serviceaccount.yaml | 9 +++++---- chart/values.yaml | 3 ++- 2 files changed, 7 insertions(+), 5 deletions(-) diff --git a/chart/templates/serviceaccount.yaml b/chart/templates/serviceaccount.yaml index 80ee5a8..af286fc 100644 --- a/chart/templates/serviceaccount.yaml +++ b/chart/templates/serviceaccount.yaml @@ -130,10 +130,11 @@ rules: - services verbs: - delete - {{- if .Values.services.icc.features.skew_protection.manage_mode }} - # Skew protection manage mode (opt-in): ICC creates versioned Deployments and - # Services. Only granted when features.skew_protection.manage_mode is true; - # observe/advise modes never need it (advise applies via the external actor). + {{- if .Values.services.icc.features.deployer.enable }} + # ICC deployer (opt-in): the deploy API creates the workload -- versioned + # Deployments and Services -- so the pod can boot and register. Independent of + # skew protection. Only granted when features.deployer.enable is true; + # observe-only installs (the customer's CI creates the workload) never need it. - apiGroups: - "" - apps diff --git a/chart/values.yaml b/chart/values.yaml index 4856e4b..4e93394 100644 --- a/chart/values.yaml +++ b/chart/values.yaml @@ -81,9 +81,10 @@ services: enable: false scaler_trends_learning: enable: false + deployer: + enable: false # ICC deployer creates workloads via the deploy API (Deployments/Services/pull Secrets). Off = observe-only, least privilege skew_protection: enable: false - manage_mode: false # Grant ICC create/update/patch on Deployments+Services (manage-mode deploys). Off = least privilege auto_cleanup: false # Delete expired Deployment and Service resources http_grace_period_ms: 1800000 # Min time to keep HTTP version draining (30 min) http_max_alive_ms: 86400000 # Hard deadline for HTTP versions (24h)