Skip to content

Commit

Permalink
[csm-authorization]: allow all powerflex paths and change default val…
Browse files Browse the repository at this point in the history
…ues (#130)

* allow powerflex paths and change default values

* update version
  • Loading branch information
atye committed Sep 21, 2022
1 parent 4579622 commit 4353cf7
Show file tree
Hide file tree
Showing 3 changed files with 11 additions and 11 deletions.
4 changes: 2 additions & 2 deletions charts/csm-authorization/Chart.yaml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
apiVersion: v2
name: csm-authorization
version: 1.3.0
appVersion: 1.3.0
version: 1.3.1
appVersion: 1.3.1
type: application
description: CSM for Authorization is part of the [Container Storage Modules](https://github.com/dell/csm) open source suite of Kubernetes storage enablers for Dell EMC storage products. CSM for Authorization provides storage and Kubernetes administrators the ability to apply RBAC for Dell CSI Drivers.
dependencies:
Expand Down
2 changes: 1 addition & 1 deletion charts/csm-authorization/policies/url.rego
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ allowlist = [
"POST /api/instances/Volume::[a-f0-9]+/action/removeVolume/"
]

default allow = false
default allow = true
allow {
regex.match(allowlist[_], sprintf("%s %s", [input.method, input.url]))
}
16 changes: 8 additions & 8 deletions charts/csm-authorization/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ authorization:

# proxy-server ingress configuration
proxyServerIngress:
ingressClassName: # nginx
ingressClassName: nginx

# additional host rules for the proxy-server ingress
hosts: []
Expand All @@ -46,15 +46,15 @@ authorization:

# tenant-service ingress configuration
tenantServiceIngress:
ingressClassName: # nginx
ingressClassName: nginx

# additional host rules for the tenant-service ingress
hosts: []

# additional annotations for the tenant-service ingress
# if applicable, an annotation supporting grpc for your ingress controller must be supplied
annotations: {}
# nginx.ingress.kubernetes.io/backend-protocol: "GRPC"
annotations:
nginx.ingress.kubernetes.io/backend-protocol: "GRPC"

# role-service ingress configuration
roleServiceIngress:
Expand All @@ -65,8 +65,8 @@ authorization:

# additional annotations for the role-service ingress
# an annotation supporting grpc for your ingress controller must be supplied, if applicable
annotations: {}
# nginx.ingress.kubernetes.io/backend-protocol: "GRPC"
annotations:
nginx.ingress.kubernetes.io/backend-protocol: "GRPC"

# storage-service ingress configuration
storageServiceIngress:
Expand All @@ -77,8 +77,8 @@ authorization:

# additional annotations for the storage-service ingress
# an annotation supporting grpc for your ingress controller must be supplied, if applicable
annotations: {}
# nginx.ingress.kubernetes.io/backend-protocol: "GRPC"
annotations:
nginx.ingress.kubernetes.io/backend-protocol: "GRPC"

redis:
images:
Expand Down

0 comments on commit 4353cf7

Please sign in to comment.