diff --git a/other/check-vpa-configuration/.chainsaw-test/chainsaw-test.yaml b/other/check-vpa-configuration/.chainsaw-test/chainsaw-test.yaml index f5fc885f1..4659846b5 100644 --- a/other/check-vpa-configuration/.chainsaw-test/chainsaw-test.yaml +++ b/other/check-vpa-configuration/.chainsaw-test/chainsaw-test.yaml @@ -6,6 +6,8 @@ spec: steps: - name: 01 - Create policy and Enforce try: + - apply: + file: permissions.yaml - apply: file: ../check-vpa-configuration.yaml - patch: diff --git a/other/check-vpa-configuration/.chainsaw-test/permissions.yaml b/other/check-vpa-configuration/.chainsaw-test/permissions.yaml new file mode 100644 index 000000000..6b20b3c83 --- /dev/null +++ b/other/check-vpa-configuration/.chainsaw-test/permissions.yaml @@ -0,0 +1,17 @@ +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: kyverno:vpa + labels: + rbac.kyverno.io/aggregate-to-background-controller: "true" + rbac.kyverno.io/aggregate-to-reports-controller: "true" + rbac.kyverno.io/aggregate-to-admission-controller: "true" +rules: +- apiGroups: + - autoscaling.k8s.io + resources: + - verticalpodautoscalers + verbs: + - get + - list + - watch \ No newline at end of file