Skip to content

Commit 23fd2c8

Browse files
committedMar 12, 2025
fix vanilla deployment - add missing service account and update cluster roles
1 parent 467ca7d commit 23fd2c8

File tree

1 file changed

+9
-0
lines changed

1 file changed

+9
-0
lines changed
 

‎manifests/vanilla/vsphere-csi-driver.yaml

+9
Original file line numberDiff line numberDiff line change
@@ -56,6 +56,10 @@ rules:
5656
- apiGroups: ["apiextensions.k8s.io"]
5757
resources: ["customresourcedefinitions"]
5858
verbs: ["get", "create", "update"]
59+
- apiGroups: ["policy"]
60+
resources: ["podsecuritypolicies"]
61+
verbs: ["use"]
62+
resourceNames: ["vmware-system-privileged"]
5963
- apiGroups: ["storage.k8s.io"]
6064
resources: ["volumeattachments/status"]
6165
verbs: ["patch"]
@@ -128,6 +132,10 @@ metadata:
128132
name: vsphere-csi-node-role
129133
namespace: vmware-system-csi
130134
rules:
135+
- apiGroups: ["policy"]
136+
resources: ["podsecuritypolicies"]
137+
verbs: ["use"]
138+
resourceNames: ["vmware-system-privileged"]
131139
- apiGroups: [""]
132140
resources: ["configmaps"]
133141
verbs: ["get", "list", "watch"]
@@ -590,6 +598,7 @@ spec:
590598
priorityClassName: system-node-critical
591599
nodeSelector:
592600
kubernetes.io/os: windows
601+
serviceAccountName: vsphere-csi-node
593602
securityContext:
594603
windowsOptions:
595604
hostProcess: true

0 commit comments

Comments
 (0)