Conversation
anxkhn
force-pushed
the
loop/kanister__002
branch
from
July 1, 2026 07:40
98428a0 to
8b2924c
Compare
anxkhn
force-pushed
the
loop/kanister__002
branch
from
August 12, 2026 05:24
8b2924c to
8a8eeda
Compare
Since the default operator RBAC was limited, the controller in the kanister namespace can no longer act on resources in the default namespace, so the tutorial errors on the first action from a clean install. Add a step granting Kanister's service account edit access in the default namespace, reusing the command pattern from docs/rbac.md. Ref kanisterio#3654 Signed-off-by: Anas Khan <83116240+anxkhn@users.noreply.github.com>
anxkhn
force-pushed
the
loop/kanister__002
branch
from
August 13, 2026 07:44
8a8eeda to
6e2321b
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Change Overview
Since #3134 limited the default RBAC granted to the Kanister operator, the
controller can no longer act on resources outside its own namespace. The
tutorial deploys
time-loggerindefaultand runs ActionSets against it fromthe
kanisternamespace, but never has the user create aRoleBinding, so afrom-scratch run errors before the first action completes.
This adds a short step right after the example app deploys: grant Kanister's
Service Account
editaccess in thedefaultnamespace. The command mirrorsthe one already documented in
docs/rbac.md, concretized to the tutorial'srelease name/namespaces, and links back to RBAC Configuration for granular
alternatives. Docs only.
Pull request type
Issues
Ref #3654
Test Plan
Built the VitePress docs locally (
cd docs && npm install && npm run docs:build):clean build, no broken-link warnings, the tutorial renders the new step and the
rbaclink resolves. Markdown only, no Go build/test impact.