Bootstraps the empty repo into a kubebuilder go/v4 project: group crawl.example.com, version v1alpha1, kind Proxy (namespaced). Keeps the existing module path and preserves the repo's Go/testing/changelog conventions from CLAUDE.md untouched. Drops the scaffolded GitHub Actions workflows since the remote is Gitea, not GitHub. Everything else is default kubebuilder output, unmodified, so later diffs stay reviewable against a known baseline. Full implementation plan: docs/plans/2026-08-07-1747-proxy-operator.md Co-Authored-By: Claude <noreply@anthropic.com>
28 lines
759 B
YAML
28 lines
759 B
YAML
# This rule is not used by the project egress-proxies-operator itself.
|
|
# It is provided to allow the cluster admin to help manage permissions for users.
|
|
#
|
|
# Grants full permissions ('*') over crawl.example.com.
|
|
# This role is intended for users authorized to modify roles and bindings within the cluster,
|
|
# enabling them to delegate specific permissions to other users or groups as needed.
|
|
|
|
apiVersion: rbac.authorization.k8s.io/v1
|
|
kind: ClusterRole
|
|
metadata:
|
|
labels:
|
|
app.kubernetes.io/name: egress-proxies-operator
|
|
app.kubernetes.io/managed-by: kustomize
|
|
name: proxy-admin-role
|
|
rules:
|
|
- apiGroups:
|
|
- crawl.example.com
|
|
resources:
|
|
- proxies
|
|
verbs:
|
|
- '*'
|
|
- apiGroups:
|
|
- crawl.example.com
|
|
resources:
|
|
- proxies/status
|
|
verbs:
|
|
- get
|