feat: add poimen-memory-admins group/permissions and k8s RBAC role
Follows the portainer/kmsvc/temporal pattern - group + "permissions" claim entry only, no Authentik Application/OAuth provider, since poimen-memory is an internal API-key service, not browser OIDC login. rock gets it automatically (already in every service_admin_group).
This commit is contained in:
@@ -14,6 +14,7 @@ resources:
|
||||
- kmsvc-operator-role.yaml
|
||||
- temporal-operator-role.yaml
|
||||
- llm-serving-operator-role.yaml
|
||||
- poimen-memory-operator-role.yaml
|
||||
# paperless's Role/RoleBinding lives in k8s/apps/paperless/rbac.yaml instead -
|
||||
# that app already has its own kustomization + namespace, no need to
|
||||
# duplicate it here. All of these stay inert (grant nothing) until
|
||||
|
||||
Reference in New Issue
Block a user