The Apigee operator's Kubernetes manager role now includes the core endpoints permission.
The Apigee operator's Kubernetes manager role now includes the core endpoints permission.
In v1.17.1, the Apigee operator's manager role is granted the core ("" API group) endpoints resource, with the verbs get, list, watch, create, update, patch, and delete. This role is the namespaced apigee-manager-role Kubernetes Role created by default in the apigee namespace. The operator needs this permission for the external (cross-cluster) Cassandra datastore feature: when a datastore uses an external host, the operator directly manages the Endpoints object of the selectorless Kubernetes Service that fronts it.
This permission is granted to all v1.17.1 installations, whether or not you use an external datastore. It is added to the operator's manager role and is not gated on any configuration property, so security teams that audit operator permissions should expect it after upgrading. Because the grant is on a namespaced Role, the new access is limited to the Apigee namespace and does not extend cluster-wide.
Most installations require no action. The apigee-operator Helm chart defines this role, so running helm upgrade on the apigee-operator chart grants the permission automatically.
If you self-manage the Apigee operator's Kubernetes RBAC, meaning you prevent Helm from creating or updating the operator's Role objects, add the endpoints resource to the existing core ("") API group rule of the apigee-manager-role Role in the Apigee namespace, or append the following rule:
- apiGroups: [""] resources: ["endpoints"] verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
If you self-manage the operator's RBAC, add this permission before you upgrade to v1.17.1. If you have already upgraded without this permission, apply the update to your role configuration to ensure proper operator functionality. Without this permission, the operator cannot manage the Endpoints object of an external datastore, so the external datastore feature does not work. If you do not use an external datastore, the operator works without this permission.