Comments (2)
Hi @Yseona, AWSChaos
and GCPChaos
require read permission on secrets, and PodChaos
pod-failure requires updates the image
field of pods.
So the rbac is expected.
I am going to close this comment, please feel free to reopen it if you have any other ideas.
from chaos-mesh.
@STRRL I recheck the code but I think the mentioned permissions are not used. Please tell me if I missed sth.
For AWSChoas
, the code uses the get
verb, but list
verb is not used.
chaos-mesh/controllers/chaosimpl/awschaos/ec2restart/impl.go
Lines 56 to 61 in 6411f53
GCPChaos
is same. list
verb seems not been used.
chaos-mesh/controllers/chaosimpl/gcpchaos/utils/utils.go
Lines 33 to 41 in 6411f53
For PodChaos
, we actually use the patch
verb. So the update
verb is indeed not used.
Among them, I think list
verb of secrets
verb may cause some security risks to some extent, since it allows users to inspect all available secrets. If it is not used, remove it might be worth-trying.
from chaos-mesh.
Related Issues (20)
- after importing a yaml in the workflow dashboard and clicked the delay object, application crashed and shows error `Cannot convert undefined or null to object`
- Failed to update records: Post https://chaos-mesh-controller-manager.chaos-mesh.svc:443/mutate-chaos-mesh-org-v1alpha1-networkchaos?timeout=5s: context deadline exceeded HOT 2
- Remote Cluster Condition Enhancement HOT 3
- IO chaos injection delete incompletely, chaosFS still exists. HOT 1
- HTTPChaos not injecting faults with an Istio sidecar HOT 2
- Unsuccessful Network Delay experiment keeps running after being paused. Deletion is also problematic HOT 2
- Chaos Mesh experiment failing with "admission webhook 'vstresschaos.kb.io' denied the request: Spec: Invalid value: xxx. missing stressors" HOT 4
- Always in a "Waiting for pod running" state
- Permission to create namespaces through RBAC. However, the error report does not have permission HOT 1
- Tracking Issue: Better observability for StressChaos HOT 1
- Failed to apply StressChaos in minikube with qemu driver: controller is not supported HOT 1
- dashboard: panic in namespace scoped mode with specific targetNamespace
- chaos-mesh go package does not work: 'go: finding module for package sigs.k8s.io/controller-runtime/pkg/envtest/printer' fails HOT 3
- Report the use of components with vulnerabilities in chaos-mesh
- controller-manager can't access RemoteCluster due to namespaced role HOT 2
- StressChaos - certificate has expired or is not yet valid HOT 1
- Memory stressor is not accepting time field HOT 2
- Not able to run HTTP Requests in Workflow HOT 1
- chaos-controller-manager CrashLoopBackOff, reporting failed to get informer from cache and too many open files
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from chaos-mesh.