Skip to content

Mechanism to allow RepoSync setup to deploy cluster scoped resource #1350

Closed Answered by sdowell
ethai asked this question in Q&A
Discussion options

You must be logged in to vote

It is by design that RepoSyncs can only manage namespace-scoped resources and not cluster-scoped resources.

For your use case you might consider setting up a RootSync with more restricted permissions using the spec.overrides.roleRefs field

Edit: See https://github.com/GoogleContainerTools/kpt-config-sync/blob/main/docs/design-docs/02-custom-root-reconciler-clusterrole.md for more context and examples

Replies: 2 comments 3 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
3 replies
@sdowell
Comment options

Answer selected by sdowell
@ethai
Comment options

@sdowell
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants