fix(operator): RCON Secret 改走无缓存按名读取,去掉 Secret watch,RBAC 收窄为 secrets get/create,不再缓存全命名空间 Secret

This commit is contained in:
Lemon-miaow committed 2026-09-25 19:25:24 +08:00
1 parent 6ec1b2726c
commit a977e229ca
6 files changed
+110 -18

No files matched your search

+5 -2
View File
@@ -117,8 +117,11 @@ func cmdOperator(args []string, _, stderr io.Writer) int {
FelisImage: os.Getenv("FELIS_IMAGE"),
// Uncached: the maintenance-lock check lists Jobs only when a server is
// about to start, which does not justify a namespace-wide Job informer.
Jobs: mgr.GetAPIReader(),
Watch: watch,
Jobs: mgr.GetAPIReader(),
// Uncached too: RCON Secrets are read by name, so the Role grants
// secrets:get without the list/watch an informer would need.
Secrets: mgr.GetAPIReader(),
Watch: watch,
}
if err := r.SetupWithManager(mgr); err != nil {
fmt.Fprintf(stderr, "felis operator: setup controller: %v\n", err)