feat(container): update image ghcr.io/pocket-id/pocket-id (v2.7.0 ➔ v2.8.0) #222

Merged
Exikle merged 1 commit from renovate-ghcr.io-pocket-id-pocket-id-2.x into main 2026-06-04 04:54:10 +00:00
Collaborator

This PR contains the following updates:

Package Update Change
ghcr.io/pocket-id/pocket-id minor v2.7.0v2.8.0

Release Notes

pocket-id/pocket-id (ghcr.io/pocket-id/pocket-id)

v2.8.0

Compare Source

Bug Fixes
Documentation
Features
Other

Full Changelog: https://github.com/pocket-id/pocket-id/compare/v2.7.0...v2.8.0


Configuration

📅 Schedule: (in timezone America/Toronto)

  • Branch creation
    • "every weekday"
  • Automerge
    • "every weekday"

🚦 Automerge: Disabled because a matching PR was automerged previously.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

This PR contains the following updates: | Package | Update | Change | |---|---|---| | [ghcr.io/pocket-id/pocket-id](https://github.com/pocket-id/pocket-id) | minor | `v2.7.0` → `v2.8.0` | --- ### Release Notes <details> <summary>pocket-id/pocket-id (ghcr.io/pocket-id/pocket-id)</summary> ### [`v2.8.0`](https://github.com/pocket-id/pocket-id/blob/HEAD/CHANGELOG.md#v280) [Compare Source](https://github.com/pocket-id/pocket-id/compare/v2.7.0...v2.8.0) ##### Bug Fixes - delete refresh tokens on end-session to prevent reuse after logout ([#&#8203;1458](https://github.com/pocket-id/pocket-id/pull/1458) by [@&#8203;wucm667](https://github.com/wucm667)) - return 404 status code for `.well-known` routes if not found ([714b5b3](https://github.com/pocket-id/pocket-id/commit/714b5b3307bb012b94e66e8dcb1de93a2d62eceb) by [@&#8203;stonith404](https://github.com/stonith404)) - add `email_verified` to reserved claims list ([8b22fca](https://github.com/pocket-id/pocket-id/commit/8b22fcaaa475984bb4c42306487035073d7c47e3) by [@&#8203;stonith404](https://github.com/stonith404)) - reject unknown PKCE code challenge methods ([ce6bdb9](https://github.com/pocket-id/pocket-id/commit/ce6bdb9d7e6c0f1eaaa21ddb6d808e41088a38b8) by [@&#8203;stonith404](https://github.com/stonith404)) - make stream of downloaded logos seekable for S3 checksum calculation ([cc9163f](https://github.com/pocket-id/pocket-id/commit/cc9163f577280d7c278dc744e20d0505dbe83ede) by [@&#8203;stonith404](https://github.com/stonith404)) - scope confirmation wasn't shown if account selection was prompted ([272d147](https://github.com/pocket-id/pocket-id/commit/272d1479bd64b4a068bfe4dfa5ba4cd3c5e90505) by [@&#8203;stonith404](https://github.com/stonith404)) - add support for unix socket mode in healthcheck ([a712196](https://github.com/pocket-id/pocket-id/commit/a71219637af1746e9faba5274b6095da676ec555) by [@&#8203;stonith404](https://github.com/stonith404)) - restore cross-platform binary builds ([7027296](https://github.com/pocket-id/pocket-id/commit/7027296632ab82cd9930f2fbe60054c2421688c4) by [@&#8203;stonith404](https://github.com/stonith404)) ##### Documentation - update SECURITY.md ([bb5a111](https://github.com/pocket-id/pocket-id/commit/bb5a111e3d51ad56fc074df7083022e3d4e25369) by [@&#8203;stonith404](https://github.com/stonith404)) ##### Features - delete OAuth refresh token on RP initiated logout ([#&#8203;1480](https://github.com/pocket-id/pocket-id/pull/1480) by [@&#8203;stonith404](https://github.com/stonith404)) - remove EXIF/XMP metadata from uploaded images ([#&#8203;1477](https://github.com/pocket-id/pocket-id/pull/1477) by [@&#8203;stonith404](https://github.com/stonith404)) - add support for `response_mode=fragment` ([0c95b7c](https://github.com/pocket-id/pocket-id/commit/0c95b7c3cc171ed77b51f236009b5ff659da0bec) by [@&#8203;stonith404](https://github.com/stonith404)) - add support for systemd socket activation ([#&#8203;1479](https://github.com/pocket-id/pocket-id/pull/1479) by [@&#8203;deviant](https://github.com/deviant)) - improve design trough the whole application ([b3d40a4](https://github.com/pocket-id/pocket-id/commit/b3d40a476b35cfa2451749e9a3d307b7babaeb6b) by [@&#8203;stonith404](https://github.com/stonith404)) ##### Other - update AAGUIDs ([#&#8203;1476](https://github.com/pocket-id/pocket-id/pull/1476) by [@&#8203;github-actions](https://github.com/github-actions)\[bot]) - upgrade dependencies ([91c2ea2](https://github.com/pocket-id/pocket-id/commit/91c2ea2a6616a500922365d1789f1fa1ba66c112) by [@&#8203;stonith404](https://github.com/stonith404)) - remove deprecated http2 package ([e56dc12](https://github.com/pocket-id/pocket-id/commit/e56dc124cee4d3c176c89e7d574ddfde089bcbd1) by [@&#8203;stonith404](https://github.com/stonith404)) - apply go 1.26.0 syntax updated ([8ad95b8](https://github.com/pocket-id/pocket-id/commit/8ad95b8af17ba8cbb62168ed0bb54c87e3df379c) by [@&#8203;stonith404](https://github.com/stonith404)) - delete refresh tokens on end-session to prevent reuse after logout ([b27a52a](https://github.com/pocket-id/pocket-id/commit/b27a52a5915228383dbdbf0a2c353452cd351d0f) by [@&#8203;stonith404](https://github.com/stonith404)) - use dependabot for automatic dependency upgrades ([b9fdd53](https://github.com/pocket-id/pocket-id/commit/b9fdd530c0f370f2fccb6251d700aa6f9bdf4124) by [@&#8203;stonith404](https://github.com/stonith404)) - fix invalid schema ([e8c398f](https://github.com/pocket-id/pocket-id/commit/e8c398ffbd6545f76c983f01556bb3b73d40a728) by [@&#8203;stonith404](https://github.com/stonith404)) - update AAGUIDs ([#&#8203;1487](https://github.com/pocket-id/pocket-id/pull/1487) by [@&#8203;github-actions](https://github.com/github-actions)\[bot]) - use custom Playwright route for callback URL checks ([f134247](https://github.com/pocket-id/pocket-id/commit/f13424720b7f5da3978988f0f9169cf303971a13) by [@&#8203;stonith404](https://github.com/stonith404)) - fix linter issues ([bc4f75c](https://github.com/pocket-id/pocket-id/commit/bc4f75c44f12a71380042ad4c140d41f4dddc7dd) by [@&#8203;stonith404](https://github.com/stonith404)) - don't compare hashes of profile pictures ([9ad2bfc](https://github.com/pocket-id/pocket-id/commit/9ad2bfc7b30e0eb2d7ae1406874b8caba5a1f121) by [@&#8203;stonith404](https://github.com/stonith404)) - run formatter ([0616aba](https://github.com/pocket-id/pocket-id/commit/0616abaf7f079d0a35543258e13aa5b4acb4adc0) by [@&#8203;stonith404](https://github.com/stonith404)) - use fixed minor version of Go ([e046a03](https://github.com/pocket-id/pocket-id/commit/e046a03364f00001f8699aaa7e902b33c2661118) by [@&#8203;stonith404](https://github.com/stonith404)) **Full Changelog**: <https://github.com/pocket-id/pocket-id/compare/v2.7.0...v2.8.0> </details> --- ### Configuration 📅 **Schedule**: (in timezone America/Toronto) - Branch creation - "every weekday" - Automerge - "every weekday" 🚦 **Automerge**: Disabled because a matching PR was automerged previously. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMTAuMiIsInVwZGF0ZWRJblZlciI6IjQzLjIxMC4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJwcmlvcml0eS9tZWRpdW0iLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL21pbm9yIl19-->
feat(container): update image ghcr.io/pocket-id/pocket-id (v2.7.0 ➔ v2.8.0)
All checks were successful
Flate / Flate - Filter (pull_request) Successful in 18s
Labeler / Labeler (pull_request_target) Successful in 32s
Flate / Flate (helmrelease) (pull_request) Successful in 2m33s
Flate / Flate (kustomization) (pull_request) Successful in 2m28s
Flate / Flate - Comment (pull_request) Successful in 29s
Flate - Success Flate checks success
Flate / Flate - Success (pull_request) Successful in 22s
d35098b554
Author
Collaborator
Kustomization diff

@@ spec.values.controllers.searxng.containers.app.image.tag @@
# helm.toolkit.fluxcd.io/v2/HelmRelease/cortex/searxng
! ± value change
- 2026.6.3-5bae05514@sha256:c6dde203961b0b138d17ecbcef31026852a4210926564af48acf58352da38b42
+ 2026.5.26-3db8b424a@sha256:9a02b1119e4928f7a4029f6a769e8741359e258792302bac80d2965c39a16493

@@ spec.image @@
# toolhive.stacklok.dev/v1beta1/MCPServer/cortex/mcp-searxng
! ± value change
- docker.io/isokoliuk/mcp-searxng:1.1.0
+ docker.io/isokoliuk/mcp-searxng:1.0.5

@@ spec.ref.tag @@
# source.toolkit.fluxcd.io/v1/OCIRepository/cortex/toolhive-operator
! ± value change
- 0.29.0
+ 0.28.3

@@ spec.ref.tag @@
# source.toolkit.fluxcd.io/v1/OCIRepository/cortex/toolhive-operator-crds
! ± value change
- 0.29.0
+ 0.28.3

@@ spec.dependsOn @@
# kustomize.toolkit.fluxcd.io/v1/Kustomization/rook-ceph/rook-ceph-cluster
! - one list entry removed:
- - name: rook-ceph-csi-drivers

@@ spec.values.controllers.home-assistant.containers.app.image.tag @@
# helm.toolkit.fluxcd.io/v2/HelmRelease/home-automation/home-assistant
! ± value change
- 2026.6.0@sha256:f89628f4623e2b99f368baa6c8ee4e6ca5856f9ad18fe9c36d0af53fe5d5ee29
+ 2026.5.4@sha256:42d1bc5e99ed0ae8f49b72b8994e25e1a6b0f1467ba26c1b959f54ca42541ffd

@@ spec.values.controllers.home-assistant.containers.codeserver.image.tag @@
# helm.toolkit.fluxcd.io/v2/HelmRelease/home-automation/home-assistant
! ± value change
- 4.123.0@sha256:6d46b83ea0687ab1826ec029b6d0e6342bbd55cc5c29b98258463e7faee16d1e
+ 4.122.1@sha256:31d3bd4039b9d41fde24ae17cc170a769a025df0782bd3bd99f0ea86f8e415a4

@@ spec.values.controllers.zigbee.containers.app.image.tag @@
# helm.toolkit.fluxcd.io/v2/HelmRelease/home-automation/zigbee
! ± value change
- 2.11.0@sha256:f1f5195076d771727e9ff3db638de0f54d37969a66f317cd34624a7af5faf364
+ 2.10.1@sha256:67c26dcf8346aced02fe1380a6afd1b57268bcef10faae3f6057c13d5d3dfa80

@@ spec.ref.tag @@
# source.toolkit.fluxcd.io/v1/OCIRepository/kube-system/renovate-operator
! ± value change
- 4.10.1
+ 4.9.0

@@ spec.values.controllers.prowlarr.containers.app.image.tag @@
# helm.toolkit.fluxcd.io/v2/HelmRelease/media/prowlarr
! ± value change
- 2.4.0.5391@sha256:91af7cbc8e357dede960033c9ecfb3a65e145d90d4e495e13adb2fbc6a546807
+ 2.3.7.5365@sha256:b9557d772c974901aed9285189d904b613f1f07750fca930eecfe78544bd3d48

@@ spec.values.controllers.app.containers.app.image.tag @@
# helm.toolkit.fluxcd.io/v2/HelmRelease/media/seerr
! ± value change
- v3.3.0@sha256:c92d2dc117f62185e7bcb88cd56efd374ea79210eaf433275449e8d5988eb5a8
+ v3.2.0@sha256:c4cbd5121236ac2f70a843a0b920b68a27976be57917555f1c45b08a1e6b2aad

@@ spec.values.provider.webhook.image.tag @@
# helm.toolkit.fluxcd.io/v2/HelmRelease/network/external-dns-unifi
! ± value change
- v0.9.0
+ v0.8.2

@@ spec.ref.tag @@
# source.toolkit.fluxcd.io/v1/OCIRepository/rook-ceph/rook-ceph-cluster
! ± value change
- v1.20.0
+ v1.19.6

@@ spec.upgrade @@
# helm.toolkit.fluxcd.io/v2/HelmRelease/rook-ceph/rook-ceph-cluster
! - one map entry removed:
- timeout: 30m

@@ spec.values @@
# helm.toolkit.fluxcd.io/v2/HelmRelease/rook-ceph/rook-ceph-cluster
! - one map entry removed:
- cephImage:
-   repository: quay.io/ceph/ceph
-   tag: v20.2.1

@@ spec.values.csi @@
# helm.toolkit.fluxcd.io/v2/HelmRelease/rook-ceph/rook-ceph
! + three map entries added:
+ cephFSKernelMountOptions: ms_mode=prefer-crc
+ enableLiveness: true
+ provisionerNodeAffinity: "kubernetes.io/hostname=talos-w-01,talos-w-02,talos-gpu-01"

@@ spec.ref.tag @@
# source.toolkit.fluxcd.io/v1/OCIRepository/rook-ceph/rook-ceph
! ± value change
- v1.20.0
+ v1.19.6

@@ data @@
# v1/ConfigMap/rook-ceph/rook-ceph-operator-config
! + one map entry added:
+ ROOK_CSI_PROVISIONER_IMAGE: "registry.k8s.io/sig-storage/csi-provisioner:v6.2.0"

@@ spec.values.controllers.pocket-id.containers.app.image.tag @@
# helm.toolkit.fluxcd.io/v2/HelmRelease/security/pocket-id
! ± value change
- v2.7.0
+ v2.8.0

@@ (root level) @@
# kustomize.toolkit.fluxcd.io/v1/Kustomization/rook-ceph/rook-ceph-csi-drivers
! - one document removed:
- apiVersion: kustomize.toolkit.fluxcd.io/v1
- kind: Kustomization
- metadata:
-   name: rook-ceph-csi-drivers
-   namespace: rook-ceph
-   labels:
-     kustomize.toolkit.fluxcd.io/name: artemis-cluster
-     kustomize.toolkit.fluxcd.io/namespace: flux-system
- spec:
-   commonMetadata:
-     labels:
-       app.kubernetes.io/name: rook-ceph-csi-drivers
-   deletionPolicy: WaitForTermination
-   dependsOn:
-   - name: rook-ceph-operator
-   interval: 1h
-   patches:
-   - patch: |
-       apiVersion: helm.toolkit.fluxcd.io/v2
-       kind: HelmRelease
-       metadata:
-         name: _
-       spec:
-         install:
-           crds: CreateReplace
-           strategy:
-             name: RetryOnFailure
-         rollback:
-           cleanupOnFail: true
-           recreate: true
-         upgrade:
-           cleanupOnFail: true
-           crds: CreateReplace
-           strategy:
-             name: RemediateOnFailure
-           remediation:
-             remediateLastFailure: true
-             retries: 2
-     target:
-       kind: HelmRelease
-       group: helm.toolkit.fluxcd.io
-   path: ./kubernetes/apps/rook-ceph/rook-ceph/csi-drivers
-   prune: true
-   retryInterval: 1m
-   sourceRef:
-     name: flux-system
-     kind: GitRepository
-     namespace: flux-system
-   targetNamespace: rook-ceph
-   timeout: 10m
-   wait: true

@@ (root level) @@
# source.toolkit.fluxcd.io/v1/HelmRepository/rook-ceph/ceph-csi-operator
! - one document removed:
- apiVersion: source.toolkit.fluxcd.io/v1
- kind: HelmRepository
- metadata:
-   name: ceph-csi-operator
-   namespace: rook-ceph
-   labels:
-     app.kubernetes.io/name: rook-ceph-csi-drivers
-     kustomize.toolkit.fluxcd.io/name: rook-ceph-csi-drivers
-     kustomize.toolkit.fluxcd.io/namespace: rook-ceph
- spec:
-   url: "https://ceph.github.io/ceph-csi-operator"
-   interval: 1h

@@ (root level) @@
# helm.toolkit.fluxcd.io/v2/HelmRelease/rook-ceph/ceph-csi-drivers
! - one document removed:
- apiVersion: helm.toolkit.fluxcd.io/v2
- kind: HelmRelease
- metadata:
-   name: ceph-csi-drivers
-   namespace: rook-ceph
-   labels:
-     app.kubernetes.io/name: rook-ceph-csi-drivers
-     kustomize.toolkit.fluxcd.io/name: rook-ceph-csi-drivers
-     kustomize.toolkit.fluxcd.io/namespace: rook-ceph
- spec:
-   chart:
-     spec:
-       version: "1.0.1"
-       chart: ceph-csi-drivers
-       sourceRef:
-         name: ceph-csi-operator
-         kind: HelmRepository
-         namespace: rook-ceph
-   install:
-     crds: CreateReplace
-     strategy:
-       name: RetryOnFailure
-   interval: 1h
-   rollback:
-     cleanupOnFail: true
-     recreate: true
-   upgrade:
-     cleanupOnFail: true
-     crds: CreateReplace
-     remediation:
-       remediateLastFailure: true
-       retries: 2
-     strategy:
-       name: RemediateOnFailure
-   values:
-     cephConnections: []
-     clientProfiles: []
-     operatorConfig:
-       driverSpecDefaults:
-         controllerPlugin:
-           affinity:
-             nodeAffinity:
-               requiredDuringSchedulingIgnoredDuringExecution:
-                 nodeSelectorTerms:
-                 - matchExpressions:
-                   - key: kubernetes.io/hostname
-                     operator: In
-                     values:
-                     - talos-w-01
-                     - talos-w-02
-                     - talos-gpu-01
-         kernelMountOptions:
-           ms_mode: prefer-crc
HelmRelease diff

@@ spec.template.spec.containers.app.image @@
# apps/v1/Deployment/cortex/searxng
! ± value change
- ghcr.io/searxng/searxng:2026.6.3-5bae05514@sha256:c6dde203961b0b138d17ecbcef31026852a4210926564af48acf58352da38b42
+ ghcr.io/searxng/searxng:2026.5.26-3db8b424a@sha256:9a02b1119e4928f7a4029f6a769e8741359e258792302bac80d2965c39a16493

@@ rules @@
# rbac.authorization.k8s.io/v1/ClusterRole/toolhive-operator-manager-role
! - three list entries removed:
- - resources:
-   - customresourcedefinitions
-   apiGroups:
-   - apiextensions.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - customresourcedefinitions/status
-   apiGroups:
-   - apiextensions.k8s.io
-   verbs:
-   - patch
-   - update
- - resources:
-   - "*"
-   apiGroups:
-   - toolhive.stacklok.dev
-   verbs:
-   - get
-   - list
-   - update

@@ spec.template.spec.containers.manager.env @@
# apps/v1/Deployment/cortex/toolhive-operator
! - one list entry removed:
- - name: TOOLHIVE_ENABLE_STORAGE_VERSION_MIGRATOR
-   value: "false"

@@ spec.template.spec.containers.manager.env.TOOLHIVE_RUNNER_IMAGE.value @@
# apps/v1/Deployment/cortex/toolhive-operator
! ± value change
- ghcr.io/stacklok/toolhive/proxyrunner:v0.29.0
+ ghcr.io/stacklok/toolhive/proxyrunner:v0.28.3

@@ spec.template.spec.containers.manager.env.VMCP_IMAGE.value @@
# apps/v1/Deployment/cortex/toolhive-operator
! ± value change
- ghcr.io/stacklok/toolhive/vmcp:v0.29.0
+ ghcr.io/stacklok/toolhive/vmcp:v0.28.3

@@ spec.template.spec.containers.manager.image @@
# apps/v1/Deployment/cortex/toolhive-operator
! ± value change
- ghcr.io/stacklok/toolhive/operator:v0.29.0
+ ghcr.io/stacklok/toolhive/operator:v0.28.3

@@ spec.template.spec.containers.app.image @@
# apps/v1/Deployment/home-automation/home-assistant
! ± value change
- ghcr.io/home-operations/home-assistant:2026.6.0@sha256:f89628f4623e2b99f368baa6c8ee4e6ca5856f9ad18fe9c36d0af53fe5d5ee29
+ ghcr.io/home-operations/home-assistant:2026.5.4@sha256:42d1bc5e99ed0ae8f49b72b8994e25e1a6b0f1467ba26c1b959f54ca42541ffd

@@ spec.template.spec.containers.codeserver.image @@
# apps/v1/Deployment/home-automation/home-assistant
! ± value change
- ghcr.io/coder/code-server:4.123.0@sha256:6d46b83ea0687ab1826ec029b6d0e6342bbd55cc5c29b98258463e7faee16d1e
+ ghcr.io/coder/code-server:4.122.1@sha256:31d3bd4039b9d41fde24ae17cc170a769a025df0782bd3bd99f0ea86f8e415a4

@@ spec.template.spec.containers.app.image @@
# apps/v1/Deployment/home-automation/zigbee
! ± value change
- ghcr.io/koenkk/zigbee2mqtt:2.11.0@sha256:f1f5195076d771727e9ff3db638de0f54d37969a66f317cd34624a7af5faf364
+ ghcr.io/koenkk/zigbee2mqtt:2.10.1@sha256:67c26dcf8346aced02fe1380a6afd1b57268bcef10faae3f6057c13d5d3dfa80

@@ spec.template.spec.containers.renovate-operator.image @@
# apps/v1/Deployment/kube-system/renovate-operator
! ± value change
- ghcr.io/mogenius/renovate-operator:4.10.1
+ ghcr.io/mogenius/renovate-operator:4.9.0

@@ data.renovatejob.yaml @@
# v1/ConfigMap/kube-system/renovate-operator-crd
! ± value change in multiline text (no inserts, one deletion)
  ---
  apiVersion: apiextensions.k8s.io/v1
  kind: CustomResourceDefinition
  metadata:
  
  [3137 lines unchanged)]
  
                    required:
                    - name
                    type: object
                  type: array
-               githubAppReference:
-                 description: |-
-                   Reference to a Github App for authentication, this will automatically mount a secret with
-                   RENOVATE_TOKEN
-                 properties:
-                   appIdSecretKey:
-                     type: string
-                   installationIdSecretKey:
-                     type: string
-                   pemSecretKey:
-                     type: string
-                   secretName:
-                     type: string
-                 required:
-                 - appIdSecretKey
-                 - installationIdSecretKey
-                 - pemSecretKey
-                 - secretName
-                 type: object
                image:
                  description: Renovate Docker image to use
                  type: string
                imagePullSecrets:
  
  [1220 lines unchanged)]
  
      served: true
      storage: true
      subresources:
        status: {}

@@ spec.template.spec.containers.app.image @@
# apps/v1/Deployment/media/prowlarr
! ± value change
- ghcr.io/home-operations/prowlarr:2.4.0.5391@sha256:91af7cbc8e357dede960033c9ecfb3a65e145d90d4e495e13adb2fbc6a546807
+ ghcr.io/home-operations/prowlarr:2.3.7.5365@sha256:b9557d772c974901aed9285189d904b613f1f07750fca930eecfe78544bd3d48

@@ spec.template.spec.containers.app.image @@
# apps/v1/Deployment/media/seerr
! ± value change
- ghcr.io/seerr-team/seerr:v3.3.0@sha256:c92d2dc117f62185e7bcb88cd56efd374ea79210eaf433275449e8d5988eb5a8
+ ghcr.io/seerr-team/seerr:v3.2.0@sha256:c4cbd5121236ac2f70a843a0b920b68a27976be57917555f1c45b08a1e6b2aad

@@ spec.template.spec.containers.webhook.image @@
# apps/v1/Deployment/network/external-dns-unifi
! ± value change
- ghcr.io/kashalls/external-dns-unifi-webhook:v0.9.0
+ ghcr.io/kashalls/external-dns-unifi-webhook:v0.8.2

@@ data @@
# v1/ConfigMap/rook-ceph/rook-ceph-operator-config
! - two map entries removed:
- ROOK_CEPH_MON_RUN_AS_ROOT: "false"
- ROOK_DELETE_UNUSED_CRUSH_RULES: "true"
! + 45 map entries added:
+ CSI_CEPHFS_ATTACH_REQUIRED: "true"
+ CSI_CEPHFS_FSGROUPPOLICY: File
+ CSI_CEPHFS_KERNEL_MOUNT_OPTIONS: ms_mode=prefer-crc
+ CSI_CEPHFS_PLUGIN_RESOURCE: |
+   - name : driver-registrar
+     resource:
+       requests:
+         memory: 128Mi
+         cpu: 50m
+       limits:
+         memory: 256Mi
+   - name : csi-cephfsplugin
+     resource:
+       requests:
+         memory: 512Mi
+         cpu: 250m
+       limits:
+         memory: 1Gi
+   - name : liveness-prometheus
+     resource:
+       requests:
+         memory: 128Mi
+         cpu: 50m
+       limits:
+         memory: 256Mi
+   
+ CSI_CEPHFS_PROVISIONER_RESOURCE: |
+   - name : csi-provisioner
+     resource:
+       requests:
+         memory: 128Mi
+         cpu: 100m
+       limits:
+         memory: 256Mi
+   - name : csi-resizer
+     resource:
+       requests:
+         memory: 128Mi
+         cpu: 100m
+       limits:
+         memory: 256Mi
+   - name : csi-attacher
+     resource:
+       requests:
+         memory: 128Mi
+         cpu: 100m
+       limits:
+         memory: 256Mi
+   - name : csi-snapshotter
+     resource:
+       requests:
+         memory: 128Mi
+         cpu: 100m
+       limits:
+         memory: 256Mi
+   - name : csi-cephfsplugin
+     resource:
+       requests:
+         memory: 512Mi
+         cpu: 250m
+       limits:
+         memory: 1Gi
+   - name : liveness-prometheus
+     resource:
+       requests:
+         memory: 128Mi
+         cpu: 50m
+       limits:
+         memory: 256Mi
+   
+ CSI_ENABLE_CEPHFS_SNAPSHOTTER: "true"
+ CSI_ENABLE_CROSS_NAMESPACE_VOLUME_DATA_SOURCE: "false"
+ CSI_ENABLE_CSIADDONS: "false"
+ CSI_ENABLE_ENCRYPTION: "false"
+ CSI_ENABLE_HOST_NETWORK: "true"
+ CSI_ENABLE_LIVENESS: "true"
+ CSI_ENABLE_METADATA: "false"
+ CSI_ENABLE_NFS_SNAPSHOTTER: "true"
+ CSI_ENABLE_OMAP_GENERATOR: "false"
+ CSI_ENABLE_RBD_SNAPSHOTTER: "true"
+ CSI_ENABLE_TOPOLOGY: "false"
+ CSI_ENABLE_VOLUME_GROUP_SNAPSHOT: "true"
+ CSI_FORCE_CEPHFS_KERNEL_CLIENT: "true"
+ CSI_GRPC_TIMEOUT_SECONDS: "150"
+ CSI_NFS_ATTACH_REQUIRED: "true"
+ CSI_NFS_FSGROUPPOLICY: File
+ CSI_NFS_PLUGIN_RESOURCE: |
+   - name : driver-registrar
+     resource:
+       requests:
+         memory: 128Mi
+         cpu: 50m
+       limits:
+         memory: 256Mi
+   - name : csi-nfsplugin
+     resource:
+       requests:
+         memory: 512Mi
+         cpu: 250m
+       limits:
+         memory: 1Gi
+   
+ CSI_NFS_PROVISIONER_RESOURCE: |
+   - name : csi-provisioner
+     resource:
+       requests:
+         memory: 128Mi
+         cpu: 100m
+       limits:
+         memory: 256Mi
+   - name : csi-nfsplugin
+     resource:
+       requests:
+         memory: 512Mi
+         cpu: 250m
+       limits:
+         memory: 1Gi
+   - name : csi-attacher
+     resource:
+       requests:
+         memory: 512Mi
+         cpu: 250m
+       limits:
+         memory: 1Gi
+   
+ CSI_PLUGIN_ENABLE_SELINUX_HOST_MOUNT: "false"
+ CSI_PLUGIN_PRIORITY_CLASSNAME: system-node-critical
+ CSI_PROVISIONER_NODE_AFFINITY: "kubernetes.io/hostname=talos-w-01,talos-w-02,talos-gpu-01"
+ CSI_PROVISIONER_PRIORITY_CLASSNAME: system-cluster-critical
+ CSI_PROVISIONER_REPLICAS: "2"
+ CSI_RBD_ATTACH_REQUIRED: "true"
+ CSI_RBD_FSGROUPPOLICY: File
+ CSI_RBD_PLUGIN_RESOURCE: |
+   - name : driver-registrar
+     resource:
+       requests:
+         memory: 128Mi
+         cpu: 50m
+       limits:
+         memory: 256Mi
+   - name : csi-rbdplugin
+     resource:
+       requests:
+         memory: 512Mi
+         cpu: 250m
+       limits:
+         memory: 1Gi
+   - name : liveness-prometheus
+     resource:
+       requests:
+         memory: 128Mi
+         cpu: 50m
+       limits:
+         memory: 256Mi
+   
+ CSI_RBD_PROVISIONER_RESOURCE: |
+   - name : csi-provisioner
+     resource:
+       requests:
+         memory: 128Mi
+         cpu: 100m
+       limits:
+         memory: 256Mi
+   - name : csi-resizer
+     resource:
+       requests:
+         memory: 128Mi
+         cpu: 100m
+       limits:
+         memory: 256Mi
+   - name : csi-attacher
+     resource:
+       requests:
+         memory: 128Mi
+         cpu: 100m
+       limits:
+         memory: 256Mi
+   - name : csi-snapshotter
+     resource:
+       requests:
+         memory: 128Mi
+         cpu: 100m
+       limits:
+         memory: 256Mi
+   - name : csi-rbdplugin
+     resource:
+       requests:
+         memory: 512Mi
+       limits:
+         memory: 1Gi
+   - name : csi-omap-generator
+     resource:
+       requests:
+         memory: 512Mi
+         cpu: 250m
+       limits:
+         memory: 1Gi
+   - name : liveness-prometheus
+     resource:
+       requests:
+         memory: 128Mi
+         cpu: 50m
+       limits:
+         memory: 256Mi
+   
+ ROOK_CSI_ATTACHER_IMAGE: "registry.k8s.io/sig-storage/csi-attacher:v4.11.0"
+ ROOK_CSI_CEPH_IMAGE: "quay.io/cephcsi/cephcsi:v3.16.2"
+ ROOK_CSI_DISABLE_DRIVER: "false"
+ ROOK_CSI_ENABLE_CEPHFS: "true"
+ ROOK_CSI_ENABLE_NFS: "false"
+ ROOK_CSI_ENABLE_RBD: "true"
+ ROOK_CSI_IMAGE_PULL_POLICY: IfNotPresent
+ ROOK_CSI_PROVISIONER_IMAGE: "registry.k8s.io/sig-storage/csi-provisioner:v6.1.1"
+ ROOK_CSI_REGISTRAR_IMAGE: "registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0"
+ ROOK_CSI_RESIZER_IMAGE: "registry.k8s.io/sig-storage/csi-resizer:v2.1.0"
+ ROOK_CSI_SNAPSHOTTER_IMAGE: "registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0"
+ ROOK_CSIADDONS_IMAGE: "quay.io/csiaddons/k8s-sidecar:v0.14.0"
+ ROOK_USE_CSI_OPERATOR: "true"

@@ rules @@
# rbac.authorization.k8s.io/v1/ClusterRole/rook-ceph-global
! - three list entries removed:
- - resources:
-   - cephclients
-   - cephclusters
-   - cephblockpools
-   - cephfilesystems
-   - cephnfses
-   - cephnvmeofgateways
-   - cephobjectstores
-   - cephobjectstoreusers
-   - cephobjectstoreaccounts
-   - cephobjectrealms
-   - cephobjectzonegroups
-   - cephobjectzones
-   - cephbuckettopics
-   - cephbucketnotifications
-   - cephrbdmirrors
-   - cephfilesystemmirrors
-   - cephfilesystemsubvolumegroups
-   - cephblockpoolradosnamespaces
-   - cephcosidrivers
-   apiGroups:
-   - ceph.rook.io
-   verbs:
-   - get
-   - list
-   - watch
-   - update
- - resources:
-   - cephclients/status
-   - cephclusters/status
-   - cephblockpools/status
-   - cephfilesystems/status
-   - cephnfses/status
-   - cephnvmeofgateways/status
-   - cephobjectstores/status
-   - cephobjectstoreusers/status
-   - cephobjectstoreaccounts/status
-   - cephobjectrealms/status
-   - cephobjectzonegroups/status
-   - cephobjectzones/status
-   - cephbuckettopics/status
-   - cephbucketnotifications/status
-   - cephrbdmirrors/status
-   - cephfilesystemmirrors/status
-   - cephfilesystemsubvolumegroups/status
-   - cephblockpoolradosnamespaces/status
-   apiGroups:
-   - ceph.rook.io
-   verbs:
-   - update
- - resources:
-   - cephclients/finalizers
-   - cephclusters/finalizers
-   - cephblockpools/finalizers
-   - cephfilesystems/finalizers
-   - cephnfses/finalizers
-   - cephnvmeofgateways/finalizers
-   - cephobjectstores/finalizers
-   - cephobjectstoreusers/finalizers
-   - cephobjectstoreaccounts/finalizers
-   - cephobjectrealms/finalizers
-   - cephobjectzonegroups/finalizers
-   - cephobjectzones/finalizers
-   - cephbuckettopics/finalizers
-   - cephbucketnotifications/finalizers
-   - cephrbdmirrors/finalizers
-   - cephfilesystemmirrors/finalizers
-   - cephfilesystemsubvolumegroups/finalizers
-   - cephblockpoolradosnamespaces/finalizers
-   apiGroups:
-   - ceph.rook.io
-   verbs:
-   - update
! + three list entries added:
+ - resources:
+   - cephclients
+   - cephclusters
+   - cephblockpools
+   - cephfilesystems
+   - cephnfses
+   - cephnvmeofgateways
+   - cephobjectstores
+   - cephobjectstoreusers
+   - cephobjectrealms
+   - cephobjectzonegroups
+   - cephobjectzones
+   - cephbuckettopics
+   - cephbucketnotifications
+   - cephrbdmirrors
+   - cephfilesystemmirrors
+   - cephfilesystemsubvolumegroups
+   - cephblockpoolradosnamespaces
+   - cephcosidrivers
+   apiGroups:
+   - ceph.rook.io
+   verbs:
+   - get
+   - list
+   - watch
+   - update
+ - resources:
+   - cephclients/status
+   - cephclusters/status
+   - cephblockpools/status
+   - cephfilesystems/status
+   - cephnfses/status
+   - cephnvmeofgateways/status
+   - cephobjectstores/status
+   - cephobjectstoreusers/status
+   - cephobjectrealms/status
+   - cephobjectzonegroups/status
+   - cephobjectzones/status
+   - cephbuckettopics/status
+   - cephbucketnotifications/status
+   - cephrbdmirrors/status
+   - cephfilesystemmirrors/status
+   - cephfilesystemsubvolumegroups/status
+   - cephblockpoolradosnamespaces/status
+   apiGroups:
+   - ceph.rook.io
+   verbs:
+   - update
+ - resources:
+   - cephclients/finalizers
+   - cephclusters/finalizers
+   - cephblockpools/finalizers
+   - cephfilesystems/finalizers
+   - cephnfses/finalizers
+   - cephnvmeofgateways/finalizers
+   - cephobjectstores/finalizers
+   - cephobjectstoreusers/finalizers
+   - cephobjectrealms/finalizers
+   - cephobjectzonegroups/finalizers
+   - cephobjectzones/finalizers
+   - cephbuckettopics/finalizers
+   - cephbucketnotifications/finalizers
+   - cephrbdmirrors/finalizers
+   - cephfilesystemmirrors/finalizers
+   - cephfilesystemsubvolumegroups/finalizers
+   - cephblockpoolradosnamespaces/finalizers
+   apiGroups:
+   - ceph.rook.io
+   verbs:
+   - update

@@ subjects @@
# rbac.authorization.k8s.io/v1/ClusterRoleBinding/ceph-csi-manager-rolebinding
! - one list entry removed:
- - name: ceph-csi
-   kind: ServiceAccount
-   namespace: rook-ceph
! + one list entry added:
+ - name: ceph-csi-controller-manager
+   kind: ServiceAccount
+   namespace: rook-ceph

@@ subjects @@
# rbac.authorization.k8s.io/v1/ClusterRoleBinding/ceph-csi-metrics-auth-rolebinding
! - one list entry removed:
- - name: ceph-csi
-   kind: ServiceAccount
-   namespace: rook-ceph
! + one list entry added:
+ - name: ceph-csi-controller-manager
+   kind: ServiceAccount
+   namespace: rook-ceph

@@ subjects @@
# rbac.authorization.k8s.io/v1/RoleBinding/rook-ceph/ceph-csi-leader-election-rolebinding
! - one list entry removed:
- - name: ceph-csi
-   kind: ServiceAccount
-   namespace: rook-ceph
! + one list entry added:
+ - name: ceph-csi-controller-manager
+   kind: ServiceAccount
+   namespace: rook-ceph

@@ spec.template.spec @@
# apps/v1/Deployment/rook-ceph/ceph-csi-controller-manager
! - four map entries removed:
- nodeSelector: {}
- priorityClassName: null
- tolerations: []
- topologySpreadConstraints: []

@@ spec.template.spec.containers.manager.env.CSI_SERVICE_ACCOUNT_PREFIX.value @@
# apps/v1/Deployment/rook-ceph/ceph-csi-controller-manager
! ± value change
- 
+ ceph-csi-

@@ spec.template.spec.containers.manager.image @@
# apps/v1/Deployment/rook-ceph/ceph-csi-controller-manager
! ± value change
- quay.io/cephcsi/ceph-csi-operator:v1.0.1
+ quay.io/cephcsi/ceph-csi-operator:v0.6.0

@@ spec.template.spec.serviceAccountName @@
# apps/v1/Deployment/rook-ceph/ceph-csi-controller-manager
! ± value change
- ceph-csi
+ ceph-csi-controller-manager

@@ spec.template.spec.containers.rook-ceph-operator.image @@
# apps/v1/Deployment/rook-ceph/rook-ceph-operator
! ± value change
- ghcr.io/rook/ceph:v1.20.0
+ ghcr.io/rook/ceph:v1.19.6

@@ spec.template.spec.containers.rook-ceph-tools.image @@
# apps/v1/Deployment/rook-ceph/rook-ceph-tools
! ± value change
- quay.io/ceph/ceph:v20.2.1
+ quay.io/ceph/ceph:v19.2.3

@@ spec.cephVersion.image @@
# ceph.rook.io/v1/CephCluster/rook-ceph/rook-ceph
! ± value change
- quay.io/ceph/ceph:v20.2.1
+ quay.io/ceph/ceph:v19.2.3

@@ spec.template.spec.containers.app.image @@
# apps/v1/Deployment/security/pocket-id
! ± value change
- ghcr.io/pocket-id/pocket-id:v2.7.0
+ ghcr.io/pocket-id/pocket-id:v2.8.0

@@ (root level) @@
# v1/ServiceAccount/rook-ceph/cephfs-csi-ceph-com-ctrlplugin-sa
! - one document removed:
- apiVersion: v1
- kind: ServiceAccount
- metadata:
-   name: cephfs-csi-ceph-com-ctrlplugin-sa
-   namespace: rook-ceph
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph

@@ (root level) @@
# v1/ServiceAccount/rook-ceph/cephfs-csi-ceph-com-nodeplugin-sa
! - one document removed:
- apiVersion: v1
- kind: ServiceAccount
- metadata:
-   name: cephfs-csi-ceph-com-nodeplugin-sa
-   namespace: rook-ceph
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph

@@ (root level) @@
# v1/ServiceAccount/rook-ceph/nfs-csi-ceph-com-ctrlplugin-sa
! - one document removed:
- apiVersion: v1
- kind: ServiceAccount
- metadata:
-   name: nfs-csi-ceph-com-ctrlplugin-sa
-   namespace: rook-ceph
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph

@@ (root level) @@
# v1/ServiceAccount/rook-ceph/nfs-csi-ceph-com-nodeplugin-sa
! - one document removed:
- apiVersion: v1
- kind: ServiceAccount
- metadata:
-   name: nfs-csi-ceph-com-nodeplugin-sa
-   namespace: rook-ceph
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph

@@ (root level) @@
# v1/ServiceAccount/rook-ceph/nvmeof-csi-ceph-com-ctrlplugin-sa
! - one document removed:
- apiVersion: v1
- kind: ServiceAccount
- metadata:
-   name: nvmeof-csi-ceph-com-ctrlplugin-sa
-   namespace: rook-ceph
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph

@@ (root level) @@
# v1/ServiceAccount/rook-ceph/nvmeof-csi-ceph-com-nodeplugin-sa
! - one document removed:
- apiVersion: v1
- kind: ServiceAccount
- metadata:
-   name: nvmeof-csi-ceph-com-nodeplugin-sa
-   namespace: rook-ceph
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph

@@ (root level) @@
# v1/ServiceAccount/rook-ceph/rbd-csi-ceph-com-ctrlplugin-sa
! - one document removed:
- apiVersion: v1
- kind: ServiceAccount
- metadata:
-   name: rbd-csi-ceph-com-ctrlplugin-sa
-   namespace: rook-ceph
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph

@@ (root level) @@
# v1/ServiceAccount/rook-ceph/rbd-csi-ceph-com-nodeplugin-sa
! - one document removed:
- apiVersion: v1
- kind: ServiceAccount
- metadata:
-   name: rbd-csi-ceph-com-nodeplugin-sa
-   namespace: rook-ceph
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRole/cephfs-csi-ceph-com-ctrlplugin-cr
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRole
- metadata:
-   name: cephfs-csi-ceph-com-ctrlplugin-cr
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- rules:
- - resources:
-   - secrets
-   apiGroups:
-   - 
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - configmaps
-   apiGroups:
-   - 
-   verbs:
-   - get
- - resources:
-   - nodes
-   apiGroups:
-   - 
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - csinodes
-   apiGroups:
-   - storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - persistentvolumes
-   apiGroups:
-   - 
-   verbs:
-   - get
-   - list
-   - watch
-   - create
-   - delete
-   - patch
-   - update
- - resources:
-   - persistentvolumeclaims
-   apiGroups:
-   - 
-   verbs:
-   - get
-   - list
-   - watch
-   - patch
-   - update
- - resources:
-   - storageclasses
-   apiGroups:
-   - storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - events
-   apiGroups:
-   - 
-   verbs:
-   - list
-   - watch
-   - create
-   - update
-   - patch
- - resources:
-   - volumeattachments
-   apiGroups:
-   - storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
-   - patch
- - resources:
-   - volumeattachments/status
-   apiGroups:
-   - storage.k8s.io
-   verbs:
-   - patch
- - resources:
-   - persistentvolumeclaims/status
-   apiGroups:
-   - 
-   verbs:
-   - patch
- - resources:
-   - volumesnapshots
-   apiGroups:
-   - snapshot.storage.k8s.io
-   verbs:
-   - get
-   - list
- - resources:
-   - volumesnapshotclasses
-   apiGroups:
-   - snapshot.storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - volumesnapshotcontents
-   apiGroups:
-   - snapshot.storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
-   - patch
-   - update
- - resources:
-   - volumesnapshotcontents/status
-   apiGroups:
-   - snapshot.storage.k8s.io
-   verbs:
-   - update
-   - patch
- - resources:
-   - volumegroupsnapshotclasses
-   apiGroups:
-   - groupsnapshot.storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - volumegroupsnapshotcontents
-   apiGroups:
-   - groupsnapshot.storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
-   - update
-   - patch
- - resources:
-   - volumegroupsnapshotcontents/status
-   apiGroups:
-   - groupsnapshot.storage.k8s.io
-   verbs:
-   - update
-   - patch
- - resources:
-   - volumegroupsnapshotclasses
-   apiGroups:
-   - groupsnapshot.storage.openshift.io
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - volumegroupsnapshotcontents
-   apiGroups:
-   - groupsnapshot.storage.openshift.io
-   verbs:
-   - get
-   - list
-   - watch
-   - update
-   - patch
- - resources:
-   - volumegroupsnapshotcontents/status
-   apiGroups:
-   - groupsnapshot.storage.openshift.io
-   verbs:
-   - update
-   - patch
- - resources:
-   - volumegroupreplicationcontents
-   apiGroups:
-   - replication.storage.openshift.io
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - volumegroupreplicationclasses
-   apiGroups:
-   - replication.storage.openshift.io
-   verbs:
-   - get
- - resources:
-   - serviceaccounts
-   apiGroups:
-   - 
-   verbs:
-   - get
- - resources:
-   - serviceaccounts/token
-   apiGroups:
-   - 
-   verbs:
-   - create
- - resources:
-   - tokenreviews
-   apiGroups:
-   - authentication.k8s.io
-   verbs:
-   - create

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRole/cephfs-csi-ceph-com-nodeplugin-cr
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRole
- metadata:
-   name: cephfs-csi-ceph-com-nodeplugin-cr
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- rules:
- - resources:
-   - nodes
-   apiGroups:
-   - 
-   verbs:
-   - get
- - resources:
-   - secrets
-   apiGroups:
-   - 
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - configmaps
-   apiGroups:
-   - 
-   verbs:
-   - get
- - resources:
-   - serviceaccounts
-   apiGroups:
-   - 
-   verbs:
-   - get
- - resources:
-   - serviceaccounts/token
-   apiGroups:
-   - 
-   verbs:
-   - create
- - resources:
-   - events
-   apiGroups:
-   - 
-   verbs:
-   - list
-   - watch
-   - create
-   - update
-   - patch
- - resources:
-   - persistentvolumes
-   - persistentvolumeclaims
-   apiGroups:
-   - 
-   verbs:
-   - get
- - resources:
-   - tokenreviews
-   apiGroups:
-   - authentication.k8s.io
-   verbs:
-   - create

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRole/nfs-csi-ceph-com-ctrlplugin-cr
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRole
- metadata:
-   name: nfs-csi-ceph-com-ctrlplugin-cr
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- rules:
- - resources:
-   - persistentvolumes
-   apiGroups:
-   - 
-   verbs:
-   - get
-   - list
-   - watch
-   - create
-   - update
-   - delete
-   - patch
- - resources:
-   - persistentvolumeclaims
-   apiGroups:
-   - 
-   verbs:
-   - get
-   - list
-   - watch
-   - patch
-   - update
- - resources:
-   - storageclasses
-   apiGroups:
-   - storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - events
-   apiGroups:
-   - 
-   verbs:
-   - get
-   - list
-   - watch
-   - create
-   - update
-   - patch
- - resources:
-   - csinodes
-   apiGroups:
-   - storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - nodes
-   apiGroups:
-   - 
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - leases
-   apiGroups:
-   - coordination.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
-   - create
-   - update
-   - patch
- - resources:
-   - secrets
-   apiGroups:
-   - 
-   verbs:
-   - get
- - resources:
-   - volumesnapshotclasses
-   apiGroups:
-   - snapshot.storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - volumesnapshotcontents
-   apiGroups:
-   - snapshot.storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
-   - update
-   - patch
- - resources:
-   - volumesnapshotcontents/status
-   apiGroups:
-   - snapshot.storage.k8s.io
-   verbs:
-   - update
-   - patch
- - resources:
-   - volumesnapshots
-   apiGroups:
-   - snapshot.storage.k8s.io
-   verbs:
-   - get
-   - list
- - resources:
-   - persistentvolumeclaims/status
-   apiGroups:
-   - 
-   verbs:
-   - patch
- - resources:
-   - volumeattachments
-   apiGroups:
-   - storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
-   - patch
- - resources:
-   - volumeattachments/status
-   apiGroups:
-   - storage.k8s.io
-   verbs:
-   - patch

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRole/nfs-csi-ceph-com-nodeplugin-cr
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRole
- metadata:
-   name: nfs-csi-ceph-com-nodeplugin-cr
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- rules:
- - resources:
-   - nodes
-   apiGroups:
-   - 
-   verbs:
-   - get

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRole/nvmeof-csi-ceph-com-ctrlplugin-cr
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRole
- metadata:
-   name: nvmeof-csi-ceph-com-ctrlplugin-cr
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- rules:
- - resources:
-   - secrets
-   apiGroups:
-   - 
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - persistentvolumes
-   apiGroups:
-   - 
-   verbs:
-   - get
-   - list
-   - watch
-   - create
-   - delete
-   - patch
-   - update
- - resources:
-   - persistentvolumeclaims
-   apiGroups:
-   - 
-   verbs:
-   - get
-   - list
-   - watch
-   - update
- - resources:
-   - storageclasses
-   apiGroups:
-   - storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - events
-   apiGroups:
-   - 
-   verbs:
-   - list
-   - watch
-   - create
-   - update
-   - patch
- - resources:
-   - volumeattachments
-   apiGroups:
-   - storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
-   - patch
- - resources:
-   - volumeattachments/status
-   apiGroups:
-   - storage.k8s.io
-   verbs:
-   - patch
- - resources:
-   - nodes
-   apiGroups:
-   - 
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - csinodes
-   apiGroups:
-   - storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - persistentvolumeclaims/status
-   apiGroups:
-   - 
-   verbs:
-   - patch
- - resources:
-   - volumesnapshots
-   apiGroups:
-   - snapshot.storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - volumesnapshotclasses
-   apiGroups:
-   - snapshot.storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - volumesnapshotcontents
-   apiGroups:
-   - snapshot.storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
-   - patch
-   - update
- - resources:
-   - volumesnapshotcontents/status
-   apiGroups:
-   - snapshot.storage.k8s.io
-   verbs:
-   - update
-   - patch
- - resources:
-   - configmaps
-   apiGroups:
-   - 
-   verbs:
-   - get
- - resources:
-   - serviceaccounts
-   apiGroups:
-   - 
-   verbs:
-   - get
- - resources:
-   - serviceaccounts/token
-   apiGroups:
-   - 
-   verbs:
-   - create
- - resources:
-   - volumegroupsnapshotclasses
-   apiGroups:
-   - groupsnapshot.storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - volumegroupsnapshotcontents
-   apiGroups:
-   - groupsnapshot.storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
-   - update
-   - patch
- - resources:
-   - volumegroupsnapshotcontents/status
-   apiGroups:
-   - groupsnapshot.storage.k8s.io
-   verbs:
-   - update
-   - patch
- - resources:
-   - volumegroupsnapshotclasses
-   apiGroups:
-   - groupsnapshot.storage.openshift.io
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - volumegroupsnapshotcontents
-   apiGroups:
-   - groupsnapshot.storage.openshift.io
-   verbs:
-   - get
-   - list
-   - watch
-   - update
-   - patch
- - resources:
-   - volumegroupsnapshotcontents/status
-   apiGroups:
-   - groupsnapshot.storage.openshift.io
-   verbs:
-   - update
-   - patch
- - resources:
-   - volumegroupreplicationcontents
-   apiGroups:
-   - replication.storage.openshift.io
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - volumegroupreplicationclasses
-   apiGroups:
-   - replication.storage.openshift.io
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - tokenreviews
-   apiGroups:
-   - authentication.k8s.io
-   verbs:
-   - create
- - resources:
-   - subjectaccessreviews
-   apiGroups:
-   - authorization.k8s.io
-   verbs:
-   - create
- - resources:
-   - snapshotmetadataservices
-   apiGroups:
-   - cbt.storage.k8s.io
-   verbs:
-   - get
-   - list

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRole/nvmeof-csi-ceph-com-nodeplugin-cr
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRole
- metadata:
-   name: nvmeof-csi-ceph-com-nodeplugin-cr
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- rules:
- - resources:
-   - secrets
-   apiGroups:
-   - 
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - persistentvolumes
-   apiGroups:
-   - 
-   verbs:
-   - get
-   - list
- - resources:
-   - volumeattachments
-   apiGroups:
-   - storage.k8s.io
-   verbs:
-   - get
-   - list
- - resources:
-   - configmaps
-   apiGroups:
-   - 
-   verbs:
-   - get
- - resources:
-   - serviceaccounts
-   apiGroups:
-   - 
-   verbs:
-   - get
- - resources:
-   - serviceaccounts/token
-   apiGroups:
-   - 
-   verbs:
-   - create
- - resources:
-   - nodes
-   apiGroups:
-   - 
-   verbs:
-   - get
- - resources:
-   - tokenreviews
-   apiGroups:
-   - authentication.k8s.io
-   verbs:
-   - create
- - resources:
-   - events
-   apiGroups:
-   - 
-   verbs:
-   - list
-   - watch
-   - create
-   - update
-   - patch
- - resources:
-   - persistentvolumeclaims
-   apiGroups:
-   - 
-   verbs:
-   - get

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRole/rbd-csi-ceph-com-ctrlplugin-cr
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRole
- metadata:
-   name: rbd-csi-ceph-com-ctrlplugin-cr
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- rules:
- - resources:
-   - secrets
-   apiGroups:
-   - 
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - persistentvolumes
-   apiGroups:
-   - 
-   verbs:
-   - get
-   - list
-   - watch
-   - create
-   - delete
-   - patch
-   - update
- - resources:
-   - persistentvolumeclaims
-   apiGroups:
-   - 
-   verbs:
-   - get
-   - list
-   - watch
-   - update
- - resources:
-   - storageclasses
-   apiGroups:
-   - storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - events
-   apiGroups:
-   - 
-   verbs:
-   - list
-   - watch
-   - create
-   - update
-   - patch
- - resources:
-   - volumeattachments
-   apiGroups:
-   - storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
-   - patch
- - resources:
-   - volumeattachments/status
-   apiGroups:
-   - storage.k8s.io
-   verbs:
-   - patch
- - resources:
-   - nodes
-   apiGroups:
-   - 
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - csinodes
-   apiGroups:
-   - storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - persistentvolumeclaims/status
-   apiGroups:
-   - 
-   verbs:
-   - patch
- - resources:
-   - volumesnapshots
-   apiGroups:
-   - snapshot.storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - volumesnapshotclasses
-   apiGroups:
-   - snapshot.storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - volumesnapshotcontents
-   apiGroups:
-   - snapshot.storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
-   - patch
-   - update
- - resources:
-   - volumesnapshotcontents/status
-   apiGroups:
-   - snapshot.storage.k8s.io
-   verbs:
-   - update
-   - patch
- - resources:
-   - configmaps
-   apiGroups:
-   - 
-   verbs:
-   - get
- - resources:
-   - serviceaccounts
-   apiGroups:
-   - 
-   verbs:
-   - get
- - resources:
-   - serviceaccounts/token
-   apiGroups:
-   - 
-   verbs:
-   - create
- - resources:
-   - volumegroupsnapshotclasses
-   apiGroups:
-   - groupsnapshot.storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - volumegroupsnapshotcontents
-   apiGroups:
-   - groupsnapshot.storage.k8s.io
-   verbs:
-   - get
-   - list
-   - watch
-   - update
-   - patch
- - resources:
-   - volumegroupsnapshotcontents/status
-   apiGroups:
-   - groupsnapshot.storage.k8s.io
-   verbs:
-   - update
-   - patch
- - resources:
-   - volumegroupsnapshotclasses
-   apiGroups:
-   - groupsnapshot.storage.openshift.io
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - volumegroupsnapshotcontents
-   apiGroups:
-   - groupsnapshot.storage.openshift.io
-   verbs:
-   - get
-   - list
-   - watch
-   - update
-   - patch
- - resources:
-   - volumegroupsnapshotcontents/status
-   apiGroups:
-   - groupsnapshot.storage.openshift.io
-   verbs:
-   - update
-   - patch
- - resources:
-   - volumegroupreplicationcontents
-   apiGroups:
-   - replication.storage.openshift.io
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - volumegroupreplicationclasses
-   apiGroups:
-   - replication.storage.openshift.io
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - tokenreviews
-   apiGroups:
-   - authentication.k8s.io
-   verbs:
-   - create
- - resources:
-   - subjectaccessreviews
-   apiGroups:
-   - authorization.k8s.io
-   verbs:
-   - create
- - resources:
-   - snapshotmetadataservices
-   apiGroups:
-   - cbt.storage.k8s.io
-   verbs:
-   - get
-   - list

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRole/rbd-csi-ceph-com-nodeplugin-cr
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRole
- metadata:
-   name: rbd-csi-ceph-com-nodeplugin-cr
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- rules:
- - resources:
-   - secrets
-   apiGroups:
-   - 
-   verbs:
-   - get
-   - list
-   - watch
- - resources:
-   - persistentvolumes
-   apiGroups:
-   - 
-   verbs:
-   - get
-   - list
- - resources:
-   - volumeattachments
-   apiGroups:
-   - storage.k8s.io
-   verbs:
-   - get
-   - list
- - resources:
-   - configmaps
-   apiGroups:
-   - 
-   verbs:
-   - get
- - resources:
-   - serviceaccounts
-   apiGroups:
-   - 
-   verbs:
-   - get
- - resources:
-   - serviceaccounts/token
-   apiGroups:
-   - 
-   verbs:
-   - create
- - resources:
-   - nodes
-   apiGroups:
-   - 
-   verbs:
-   - get
- - resources:
-   - tokenreviews
-   apiGroups:
-   - authentication.k8s.io
-   verbs:
-   - create
- - resources:
-   - events
-   apiGroups:
-   - 
-   verbs:
-   - list
-   - watch
-   - create
-   - update
-   - patch
- - resources:
-   - persistentvolumeclaims
-   apiGroups:
-   - 
-   verbs:
-   - get

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRoleBinding/cephfs-csi-ceph-com-ctrlplugin-crb
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRoleBinding
- metadata:
-   name: cephfs-csi-ceph-com-ctrlplugin-crb
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- roleRef:
-   name: cephfs-csi-ceph-com-ctrlplugin-cr
-   apiGroup: rbac.authorization.k8s.io
-   kind: ClusterRole
- subjects:
- - name: cephfs-csi-ceph-com-ctrlplugin-sa
-   kind: ServiceAccount
-   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRoleBinding/cephfs-csi-ceph-com-nodeplugin-crb
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRoleBinding
- metadata:
-   name: cephfs-csi-ceph-com-nodeplugin-crb
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- roleRef:
-   name: cephfs-csi-ceph-com-nodeplugin-cr
-   apiGroup: rbac.authorization.k8s.io
-   kind: ClusterRole
- subjects:
- - name: cephfs-csi-ceph-com-nodeplugin-sa
-   kind: ServiceAccount
-   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRoleBinding/nfs-csi-ceph-com-ctrlplugin-crb
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRoleBinding
- metadata:
-   name: nfs-csi-ceph-com-ctrlplugin-crb
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- roleRef:
-   name: nfs-csi-ceph-com-ctrlplugin-cr
-   apiGroup: rbac.authorization.k8s.io
-   kind: ClusterRole
- subjects:
- - name: nfs-csi-ceph-com-ctrlplugin-sa
-   kind: ServiceAccount
-   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRoleBinding/nfs-csi-ceph-com-nodeplugin-crb
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRoleBinding
- metadata:
-   name: nfs-csi-ceph-com-nodeplugin-crb
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- roleRef:
-   name: nfs-csi-ceph-com-nodeplugin-cr
-   apiGroup: rbac.authorization.k8s.io
-   kind: ClusterRole
- subjects:
- - name: nfs-csi-ceph-com-nodeplugin-sa
-   kind: ServiceAccount
-   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRoleBinding/nvmeof-csi-ceph-com-ctrlplugin-crb
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRoleBinding
- metadata:
-   name: nvmeof-csi-ceph-com-ctrlplugin-crb
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- roleRef:
-   name: nvmeof-csi-ceph-com-ctrlplugin-cr
-   apiGroup: rbac.authorization.k8s.io
-   kind: ClusterRole
- subjects:
- - name: nvmeof-csi-ceph-com-ctrlplugin-sa
-   kind: ServiceAccount
-   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRoleBinding/nvmeof-csi-ceph-com-nodeplugin-crb
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRoleBinding
- metadata:
-   name: nvmeof-csi-ceph-com-nodeplugin-crb
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- roleRef:
-   name: nvmeof-csi-ceph-com-nodeplugin-cr
-   apiGroup: rbac.authorization.k8s.io
-   kind: ClusterRole
- subjects:
- - name: nvmeof-csi-ceph-com-nodeplugin-sa
-   kind: ServiceAccount
-   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRoleBinding/rbd-csi-ceph-com-ctrlplugin-crb
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRoleBinding
- metadata:
-   name: rbd-csi-ceph-com-ctrlplugin-crb
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- roleRef:
-   name: rbd-csi-ceph-com-ctrlplugin-cr
-   apiGroup: rbac.authorization.k8s.io
-   kind: ClusterRole
- subjects:
- - name: rbd-csi-ceph-com-ctrlplugin-sa
-   kind: ServiceAccount
-   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRoleBinding/rbd-csi-ceph-com-nodeplugin-crb
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRoleBinding
- metadata:
-   name: rbd-csi-ceph-com-nodeplugin-crb
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- roleRef:
-   name: rbd-csi-ceph-com-nodeplugin-cr
-   apiGroup: rbac.authorization.k8s.io
-   kind: ClusterRole
- subjects:
- - name: rbd-csi-ceph-com-nodeplugin-sa
-   kind: ServiceAccount
-   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/Role/cephfs-csi-ceph-com-ctrlplugin-r
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: Role
- metadata:
-   name: cephfs-csi-ceph-com-ctrlplugin-r
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- rules:
- - resources:
-   - leases
-   apiGroups:
-   - coordination.k8s.io
-   verbs:
-   - get
-   - watch
-   - list
-   - delete
-   - update
-   - create
- - resources:
-   - csiaddonsnodes
-   apiGroups:
-   - csiaddons.openshift.io
-   verbs:
-   - get
-   - watch
-   - list
-   - create
-   - update
-   - delete
- - resources:
-   - pods
-   apiGroups:
-   - 
-   verbs:
-   - get
- - resources:
-   - replicasets
-   apiGroups:
-   - apps
-   verbs:
-   - get
- - resources:
-   - deployments/finalizers
-   - daemonsets/finalizers
-   apiGroups:
-   - apps
-   verbs:
-   - update

@@ (root level) @@
# rbac.authorization.k8s.io/v1/Role/cephfs-csi-ceph-com-nodeplugin-r
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: Role
- metadata:
-   name: cephfs-csi-ceph-com-nodeplugin-r
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- rules:
- - resources:
-   - csiaddonsnodes
-   apiGroups:
-   - csiaddons.openshift.io
-   verbs:
-   - get
-   - watch
-   - list
-   - create
-   - update
-   - delete
- - resources:
-   - pods
-   apiGroups:
-   - 
-   verbs:
-   - get
- - resources:
-   - replicasets
-   apiGroups:
-   - apps
-   verbs:
-   - get
- - resources:
-   - deployments/finalizers
-   - daemonsets/finalizers
-   apiGroups:
-   - apps
-   verbs:
-   - update

@@ (root level) @@
# rbac.authorization.k8s.io/v1/Role/nvmeof-csi-ceph-com-ctrlplugin-r
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: Role
- metadata:
-   name: nvmeof-csi-ceph-com-ctrlplugin-r
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- rules:
- - resources:
-   - leases
-   apiGroups:
-   - coordination.k8s.io
-   verbs:
-   - get
-   - watch
-   - list
-   - delete
-   - update
-   - create
- - resources:
-   - csiaddonsnodes
-   apiGroups:
-   - csiaddons.openshift.io
-   verbs:
-   - get
-   - watch
-   - list
-   - create
-   - update
-   - delete
- - resources:
-   - pods
-   apiGroups:
-   - 
-   verbs:
-   - get
- - resources:
-   - replicasets
-   apiGroups:
-   - apps
-   verbs:
-   - get
- - resources:
-   - deployments/finalizers
-   - daemonsets/finalizers
-   apiGroups:
-   - apps
-   verbs:
-   - update

@@ (root level) @@
# rbac.authorization.k8s.io/v1/Role/nvmeof-csi-ceph-com-nodeplugin-r
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: Role
- metadata:
-   name: nvmeof-csi-ceph-com-nodeplugin-r
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- rules:
- - resources:
-   - csiaddonsnodes
-   apiGroups:
-   - csiaddons.openshift.io
-   verbs:
-   - get
-   - watch
-   - list
-   - create
-   - update
-   - delete
- - resources:
-   - pods
-   apiGroups:
-   - 
-   verbs:
-   - get
- - resources:
-   - replicasets
-   apiGroups:
-   - apps
-   verbs:
-   - get
- - resources:
-   - deployments/finalizers
-   - daemonsets/finalizers
-   apiGroups:
-   - apps
-   verbs:
-   - update

@@ (root level) @@
# rbac.authorization.k8s.io/v1/Role/rbd-csi-ceph-com-ctrlplugin-r
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: Role
- metadata:
-   name: rbd-csi-ceph-com-ctrlplugin-r
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- rules:
- - resources:
-   - leases
-   apiGroups:
-   - coordination.k8s.io
-   verbs:
-   - get
-   - watch
-   - list
-   - delete
-   - update
-   - create
- - resources:
-   - csiaddonsnodes
-   apiGroups:
-   - csiaddons.openshift.io
-   verbs:
-   - get
-   - watch
-   - list
-   - create
-   - update
-   - delete
- - resources:
-   - pods
-   apiGroups:
-   - 
-   verbs:
-   - get
- - resources:
-   - replicasets
-   apiGroups:
-   - apps
-   verbs:
-   - get
- - resources:
-   - deployments/finalizers
-   - daemonsets/finalizers
-   apiGroups:
-   - apps
-   verbs:
-   - update

@@ (root level) @@
# rbac.authorization.k8s.io/v1/Role/rbd-csi-ceph-com-nodeplugin-r
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: Role
- metadata:
-   name: rbd-csi-ceph-com-nodeplugin-r
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- rules:
- - resources:
-   - csiaddonsnodes
-   apiGroups:
-   - csiaddons.openshift.io
-   verbs:
-   - get
-   - watch
-   - list
-   - create
-   - update
-   - delete
- - resources:
-   - pods
-   apiGroups:
-   - 
-   verbs:
-   - get
- - resources:
-   - replicasets
-   apiGroups:
-   - apps
-   verbs:
-   - get
- - resources:
-   - deployments/finalizers
-   - daemonsets/finalizers
-   apiGroups:
-   - apps
-   verbs:
-   - update

@@ (root level) @@
# rbac.authorization.k8s.io/v1/RoleBinding/cephfs-csi-ceph-com-ctrlplugin-rb
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: RoleBinding
- metadata:
-   name: cephfs-csi-ceph-com-ctrlplugin-rb
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- roleRef:
-   name: cephfs-csi-ceph-com-ctrlplugin-r
-   apiGroup: rbac.authorization.k8s.io
-   kind: Role
- subjects:
- - name: cephfs-csi-ceph-com-ctrlplugin-sa
-   kind: ServiceAccount
-   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/RoleBinding/cephfs-csi-ceph-com-nodeplugin-rb
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: RoleBinding
- metadata:
-   name: cephfs-csi-ceph-com-nodeplugin-rb
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- roleRef:
-   name: cephfs-csi-ceph-com-nodeplugin-r
-   apiGroup: rbac.authorization.k8s.io
-   kind: Role
- subjects:
- - name: cephfs-csi-ceph-com-nodeplugin-sa
-   kind: ServiceAccount
-   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/RoleBinding/nvmeof-csi-ceph-com-ctrlplugin-rb
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: RoleBinding
- metadata:
-   name: nvmeof-csi-ceph-com-ctrlplugin-rb
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- roleRef:
-   name: nvmeof-csi-ceph-com-ctrlplugin-r
-   apiGroup: rbac.authorization.k8s.io
-   kind: Role
- subjects:
- - name: nvmeof-csi-ceph-com-ctrlplugin-sa
-   kind: ServiceAccount
-   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/RoleBinding/nvmeof-csi-ceph-com-nodeplugin-rb
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: RoleBinding
- metadata:
-   name: nvmeof-csi-ceph-com-nodeplugin-rb
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- roleRef:
-   name: nvmeof-csi-ceph-com-nodeplugin-r
-   apiGroup: rbac.authorization.k8s.io
-   kind: Role
- subjects:
- - name: nvmeof-csi-ceph-com-nodeplugin-sa
-   kind: ServiceAccount
-   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/RoleBinding/rbd-csi-ceph-com-ctrlplugin-rb
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: RoleBinding
- metadata:
-   name: rbd-csi-ceph-com-ctrlplugin-rb
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- roleRef:
-   name: rbd-csi-ceph-com-ctrlplugin-r
-   apiGroup: rbac.authorization.k8s.io
-   kind: Role
- subjects:
- - name: rbd-csi-ceph-com-ctrlplugin-sa
-   kind: ServiceAccount
-   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/RoleBinding/rbd-csi-ceph-com-nodeplugin-rb
! - one document removed:
- apiVersion: rbac.authorization.k8s.io/v1
- kind: RoleBinding
- metadata:
-   name: rbd-csi-ceph-com-nodeplugin-rb
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- roleRef:
-   name: rbd-csi-ceph-com-nodeplugin-r
-   apiGroup: rbac.authorization.k8s.io
-   kind: Role
- subjects:
- - name: rbd-csi-ceph-com-nodeplugin-sa
-   kind: ServiceAccount
-   namespace: rook-ceph

@@ (root level) @@
# csi.ceph.io/v1/Driver/rook-ceph/cephfs.csi.ceph.com
! - one document removed:
- apiVersion: csi.ceph.io/v1
- kind: Driver
- metadata:
-   name: cephfs.csi.ceph.com
-   namespace: rook-ceph
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- spec:
-   attachRequired: true
-   cephFsClientType: kernel
-   controllerPlugin:
-     hostNetwork: false
-     privileged: false
-     replicas: 1
-     serviceAccountName: cephfs-csi-ceph-com-ctrlplugin-sa
-     tolerations: []
-     volumes: []
-   deployCsiAddons: false
-   enableFencing: false
-   fsGroupPolicy: None
-   fuseMountOptions: {}
-   generateOMapInfo: false
-   grpcTimeout: 30
-   kernelMountOptions: {}
-   log:
-     rotation:
-       maxFiles: 7
-       maxLogSize: 10Gi
-       periodicity: daily
-     verbosity: 0
-   nodePlugin:
-     imagePullPolicy: IfNotPresent
-     serviceAccountName: cephfs-csi-ceph-com-nodeplugin-sa
-     tolerations: []
-     volumes: []
-   snapshotPolicy: volumeSnapshot

@@ (root level) @@
# csi.ceph.io/v1/Driver/rook-ceph/nfs.csi.ceph.com
! - one document removed:
- apiVersion: csi.ceph.io/v1
- kind: Driver
- metadata:
-   name: nfs.csi.ceph.com
-   namespace: rook-ceph
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- spec:
-   attachRequired: true
-   cephFsClientType: kernel
-   controllerPlugin:
-     hostNetwork: false
-     privileged: false
-     replicas: 1
-     serviceAccountName: nfs-csi-ceph-com-ctrlplugin-sa
-     tolerations: []
-     volumes: []
-   deployCsiAddons: false
-   enableFencing: false
-   fsGroupPolicy: None
-   fuseMountOptions: {}
-   generateOMapInfo: false
-   grpcTimeout: 30
-   kernelMountOptions: {}
-   log:
-     rotation:
-       maxFiles: 7
-       maxLogSize: 10Gi
-       periodicity: daily
-     verbosity: 0
-   nodePlugin:
-     imagePullPolicy: IfNotPresent
-     serviceAccountName: nfs-csi-ceph-com-nodeplugin-sa
-     tolerations: []
-     volumes: []
-   snapshotPolicy: volumeSnapshot

@@ (root level) @@
# csi.ceph.io/v1/Driver/rook-ceph/nvmeof.csi.ceph.com
! - one document removed:
- apiVersion: csi.ceph.io/v1
- kind: Driver
- metadata:
-   name: nvmeof.csi.ceph.com
-   namespace: rook-ceph
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- spec:
-   attachRequired: true
-   cephFsClientType: kernel
-   controllerPlugin:
-     hostNetwork: false
-     privileged: false
-     replicas: 1
-     serviceAccountName: nvmeof-csi-ceph-com-ctrlplugin-sa
-     tolerations: []
-     volumes: []
-   deployCsiAddons: false
-   enableFencing: false
-   fsGroupPolicy: File
-   fuseMountOptions: {}
-   generateOMapInfo: false
-   grpcTimeout: 30
-   kernelMountOptions: {}
-   log:
-     rotation:
-       maxFiles: 7
-       maxLogSize: 10Gi
-       periodicity: daily
-     verbosity: 0
-   nodePlugin:
-     imagePullPolicy: IfNotPresent
-     serviceAccountName: nvmeof-csi-ceph-com-nodeplugin-sa
-     tolerations: []
-     volumes: []
-   snapshotPolicy: none

@@ (root level) @@
# csi.ceph.io/v1/Driver/rook-ceph/rbd.csi.ceph.com
! - one document removed:
- apiVersion: csi.ceph.io/v1
- kind: Driver
- metadata:
-   name: rbd.csi.ceph.com
-   namespace: rook-ceph
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- spec:
-   attachRequired: true
-   cephFsClientType: kernel
-   controllerPlugin:
-     hostNetwork: false
-     privileged: false
-     replicas: 1
-     serviceAccountName: rbd-csi-ceph-com-ctrlplugin-sa
-     tolerations: []
-     volumes: []
-   deployCsiAddons: false
-   enableFencing: false
-   fsGroupPolicy: File
-   fuseMountOptions: {}
-   generateOMapInfo: false
-   grpcTimeout: 30
-   kernelMountOptions: {}
-   log:
-     rotation:
-       maxFiles: 7
-       maxLogSize: 10Gi
-       periodicity: daily
-     verbosity: 0
-   nodePlugin:
-     imagePullPolicy: IfNotPresent
-     serviceAccountName: rbd-csi-ceph-com-nodeplugin-sa
-     tolerations: []
-     volumes: []
-   snapshotPolicy: none

@@ (root level) @@
# csi.ceph.io/v1/OperatorConfig/null/ceph-csi-operator-config
! - one document removed:
- apiVersion: csi.ceph.io/v1
- kind: OperatorConfig
- metadata:
-   name: ceph-csi-operator-config
-   namespace: null
-   labels:
-     helm.toolkit.fluxcd.io/name: ceph-csi-drivers
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- spec:
-   driverSpecDefaults:
-     attachRequired: true
-     cephFsClientType: kernel
-     controllerPlugin:
-       affinity:
-         nodeAffinity:
-           requiredDuringSchedulingIgnoredDuringExecution:
-             nodeSelectorTerms:
-             - matchExpressions:
-               - key: kubernetes.io/hostname
-                 operator: In
-                 values:
-                 - talos-w-01
-                 - talos-w-02
-                 - talos-gpu-01
-       hostNetwork: false
-       imagePullPolicy: IfNotPresent
-       privileged: false
-       replicas: 1
-       tolerations: []
-       volumes: []
-     deployCsiAddons: false
-     enableFencing: false
-     fsGroupPolicy: File
-     fuseMountOptions: {}
-     generateOMapInfo: false
-     grpcTimeout: 30
-     kernelMountOptions:
-       ms_mode: prefer-crc
-     log:
-       rotation:
-         maxFiles: 7
-         maxLogSize: 10Gi
-         periodicity: daily
-       verbosity: 0
-     nodePlugin:
-       imagePullPolicy: IfNotPresent
-       kubeletDirPath: /var/lib/kubelet
-       tolerations: []
-       volumes: []
-     snapshotPolicy: none

@@ (root level) @@
# v1/ServiceAccount/ceph-csi
! - one document removed:
- apiVersion: v1
- kind: ServiceAccount
- metadata:
-   name: ceph-csi
-   labels:
-     app.kubernetes.io/instance: rook-ceph
-     app.kubernetes.io/managed-by: Helm
-     app.kubernetes.io/name: ceph-csi
-     helm.toolkit.fluxcd.io/name: rook-ceph
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
- automountServiceAccountToken: true

@@ (root level) @@
# v1/ConfigMap/rook-ceph/rook-csi-operator-image-set-configmap
! - one document removed:
- apiVersion: v1
- kind: ConfigMap
- metadata:
-   name: rook-csi-operator-image-set-configmap
-   namespace: rook-ceph
-   labels:
-     app.kubernetes.io/created-by: helm
-     app.kubernetes.io/instance: rook-ceph
-     app.kubernetes.io/managed-by: Helm
-     app.kubernetes.io/name: rook-ceph
-     app.kubernetes.io/part-of: rook-ceph-operator
-     helm.toolkit.fluxcd.io/name: rook-ceph
-     helm.toolkit.fluxcd.io/namespace: rook-ceph
-     operator: rook
-     storage-backend: ceph
- data:
-   addons: "quay.io/csiaddons/k8s-sidecar:v0.14.0"
-   attacher: "registry.k8s.io/sig-storage/csi-attacher:v4.12.0"
-   plugin: "quay.io/cephcsi/cephcsi:v3.17.0"
-   provisioner: "registry.k8s.io/sig-storage/csi-provisioner:v6.2.0"
-   registrar: "registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0"
-   resizer: "registry.k8s.io/sig-storage/csi-resizer:v2.1.0"
-   snapshotter: "registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0"

@@ (root level) @@
# v1/ServiceAccount/rook-ceph/ceph-csi-cephfs-ctrlplugin-sa
! + one document added:
+ apiVersion: v1
+ kind: ServiceAccount
+ metadata:
+   name: ceph-csi-cephfs-ctrlplugin-sa
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph

@@ (root level) @@
# v1/ServiceAccount/rook-ceph/ceph-csi-cephfs-nodeplugin-sa
! + one document added:
+ apiVersion: v1
+ kind: ServiceAccount
+ metadata:
+   name: ceph-csi-cephfs-nodeplugin-sa
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph

@@ (root level) @@
# v1/ServiceAccount/rook-ceph/ceph-csi-controller-manager
! + one document added:
+ apiVersion: v1
+ kind: ServiceAccount
+ metadata:
+   name: ceph-csi-controller-manager
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph

@@ (root level) @@
# v1/ServiceAccount/rook-ceph/ceph-csi-nfs-ctrlplugin-sa
! + one document added:
+ apiVersion: v1
+ kind: ServiceAccount
+ metadata:
+   name: ceph-csi-nfs-ctrlplugin-sa
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph

@@ (root level) @@
# v1/ServiceAccount/rook-ceph/ceph-csi-nfs-nodeplugin-sa
! + one document added:
+ apiVersion: v1
+ kind: ServiceAccount
+ metadata:
+   name: ceph-csi-nfs-nodeplugin-sa
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph

@@ (root level) @@
# v1/ServiceAccount/rook-ceph/ceph-csi-nvmeof-ctrlplugin-sa
! + one document added:
+ apiVersion: v1
+ kind: ServiceAccount
+ metadata:
+   name: ceph-csi-nvmeof-ctrlplugin-sa
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph

@@ (root level) @@
# v1/ServiceAccount/rook-ceph/ceph-csi-nvmeof-nodeplugin-sa
! + one document added:
+ apiVersion: v1
+ kind: ServiceAccount
+ metadata:
+   name: ceph-csi-nvmeof-nodeplugin-sa
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph

@@ (root level) @@
# v1/ServiceAccount/rook-ceph/ceph-csi-rbd-ctrlplugin-sa
! + one document added:
+ apiVersion: v1
+ kind: ServiceAccount
+ metadata:
+   name: ceph-csi-rbd-ctrlplugin-sa
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph

@@ (root level) @@
# v1/ServiceAccount/rook-ceph/ceph-csi-rbd-nodeplugin-sa
! + one document added:
+ apiVersion: v1
+ kind: ServiceAccount
+ metadata:
+   name: ceph-csi-rbd-nodeplugin-sa
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph

@@ (root level) @@
# v1/ServiceAccount/rook-ceph/rook-csi-cephfs-plugin-sa
! + one document added:
+ apiVersion: v1
+ kind: ServiceAccount
+ metadata:
+   name: rook-csi-cephfs-plugin-sa
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/created-by: helm
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: rook-ceph
+     app.kubernetes.io/part-of: rook-ceph-operator
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+     operator: rook
+     storage-backend: ceph

@@ (root level) @@
# v1/ServiceAccount/rook-ceph/rook-csi-cephfs-provisioner-sa
! + one document added:
+ apiVersion: v1
+ kind: ServiceAccount
+ metadata:
+   name: rook-csi-cephfs-provisioner-sa
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/created-by: helm
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: rook-ceph
+     app.kubernetes.io/part-of: rook-ceph-operator
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+     operator: rook
+     storage-backend: ceph

@@ (root level) @@
# v1/ServiceAccount/rook-ceph/rook-csi-rbd-plugin-sa
! + one document added:
+ apiVersion: v1
+ kind: ServiceAccount
+ metadata:
+   name: rook-csi-rbd-plugin-sa
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/created-by: helm
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: rook-ceph
+     app.kubernetes.io/part-of: rook-ceph-operator
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+     operator: rook
+     storage-backend: ceph

@@ (root level) @@
# v1/ServiceAccount/rook-ceph/rook-csi-rbd-provisioner-sa
! + one document added:
+ apiVersion: v1
+ kind: ServiceAccount
+ metadata:
+   name: rook-csi-rbd-provisioner-sa
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/created-by: helm
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: rook-ceph
+     app.kubernetes.io/part-of: rook-ceph-operator
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+     operator: rook
+     storage-backend: ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRole/ceph-csi-cephfs-ctrlplugin-cr
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRole
+ metadata:
+   name: ceph-csi-cephfs-ctrlplugin-cr
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ rules:
+ - resources:
+   - secrets
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - configmaps
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - nodes
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - csinodes
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - persistentvolumes
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+   - watch
+   - create
+   - delete
+   - patch
+   - update
+ - resources:
+   - persistentvolumeclaims
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+   - watch
+   - patch
+   - update
+ - resources:
+   - storageclasses
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - events
+   apiGroups:
+   - 
+   verbs:
+   - list
+   - watch
+   - create
+   - update
+   - patch
+ - resources:
+   - volumeattachments
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+   - patch
+ - resources:
+   - volumeattachments/status
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - patch
+ - resources:
+   - persistentvolumeclaims/status
+   apiGroups:
+   - 
+   verbs:
+   - patch
+ - resources:
+   - volumesnapshots
+   apiGroups:
+   - snapshot.storage.k8s.io
+   verbs:
+   - get
+   - list
+ - resources:
+   - volumesnapshotclasses
+   apiGroups:
+   - snapshot.storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - volumesnapshotcontents
+   apiGroups:
+   - snapshot.storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+   - patch
+   - update
+ - resources:
+   - volumesnapshotcontents/status
+   apiGroups:
+   - snapshot.storage.k8s.io
+   verbs:
+   - update
+   - patch
+ - resources:
+   - volumegroupsnapshotclasses
+   apiGroups:
+   - groupsnapshot.storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - volumegroupsnapshotcontents
+   apiGroups:
+   - groupsnapshot.storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+   - update
+   - patch
+ - resources:
+   - volumegroupsnapshotcontents/status
+   apiGroups:
+   - groupsnapshot.storage.k8s.io
+   verbs:
+   - update
+   - patch
+ - resources:
+   - volumegroupsnapshotclasses
+   apiGroups:
+   - groupsnapshot.storage.openshift.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - volumegroupsnapshotcontents
+   apiGroups:
+   - groupsnapshot.storage.openshift.io
+   verbs:
+   - get
+   - list
+   - watch
+   - update
+   - patch
+ - resources:
+   - volumegroupsnapshotcontents/status
+   apiGroups:
+   - groupsnapshot.storage.openshift.io
+   verbs:
+   - update
+   - patch
+ - resources:
+   - serviceaccounts
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - serviceaccounts/token
+   apiGroups:
+   - 
+   verbs:
+   - create
+ - resources:
+   - tokenreviews
+   apiGroups:
+   - authentication.k8s.io
+   verbs:
+   - create
+ - resources:
+   - volumeattributesclasses
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRole/ceph-csi-cephfs-nodeplugin-cr
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRole
+ metadata:
+   name: ceph-csi-cephfs-nodeplugin-cr
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ rules:
+ - resources:
+   - nodes
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - secrets
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - configmaps
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - serviceaccounts
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - serviceaccounts/token
+   apiGroups:
+   - 
+   verbs:
+   - create
+ - resources:
+   - events
+   apiGroups:
+   - 
+   verbs:
+   - list
+   - watch
+   - create
+   - update
+   - patch
+ - resources:
+   - persistentvolumes
+   - persistentvolumeclaims
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - tokenreviews
+   apiGroups:
+   - authentication.k8s.io
+   verbs:
+   - create

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRole/ceph-csi-nfs-ctrlplugin-cr
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRole
+ metadata:
+   name: ceph-csi-nfs-ctrlplugin-cr
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ rules:
+ - resources:
+   - persistentvolumes
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+   - watch
+   - create
+   - update
+   - delete
+   - patch
+ - resources:
+   - persistentvolumeclaims
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+   - watch
+   - patch
+   - update
+ - resources:
+   - storageclasses
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - events
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+   - watch
+   - create
+   - update
+   - patch
+ - resources:
+   - csinodes
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - nodes
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - leases
+   apiGroups:
+   - coordination.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+   - create
+   - update
+   - patch
+ - resources:
+   - secrets
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - volumesnapshotclasses
+   apiGroups:
+   - snapshot.storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - volumesnapshotcontents
+   apiGroups:
+   - snapshot.storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+   - update
+   - patch
+ - resources:
+   - volumesnapshotcontents/status
+   apiGroups:
+   - snapshot.storage.k8s.io
+   verbs:
+   - update
+   - patch
+ - resources:
+   - volumesnapshots
+   apiGroups:
+   - snapshot.storage.k8s.io
+   verbs:
+   - get
+   - list
+ - resources:
+   - persistentvolumeclaims/status
+   apiGroups:
+   - 
+   verbs:
+   - patch
+ - resources:
+   - volumeattachments
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+   - patch
+ - resources:
+   - volumeattachments/status
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - patch
+ - resources:
+   - volumeattributesclasses
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRole/ceph-csi-nfs-nodeplugin-cr
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRole
+ metadata:
+   name: ceph-csi-nfs-nodeplugin-cr
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ rules:
+ - resources:
+   - nodes
+   apiGroups:
+   - 
+   verbs:
+   - get

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRole/ceph-csi-nvmeof-ctrlplugin-cr
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRole
+ metadata:
+   name: ceph-csi-nvmeof-ctrlplugin-cr
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ rules:
+ - resources:
+   - secrets
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - persistentvolumes
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+   - watch
+   - create
+   - delete
+   - patch
+   - update
+ - resources:
+   - persistentvolumeclaims
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+   - watch
+   - update
+ - resources:
+   - storageclasses
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - events
+   apiGroups:
+   - 
+   verbs:
+   - list
+   - watch
+   - create
+   - update
+   - patch
+ - resources:
+   - volumeattachments
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+   - patch
+ - resources:
+   - volumeattachments/status
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - patch
+ - resources:
+   - nodes
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - csinodes
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - persistentvolumeclaims/status
+   apiGroups:
+   - 
+   verbs:
+   - patch
+ - resources:
+   - configmaps
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - serviceaccounts
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - serviceaccounts/token
+   apiGroups:
+   - 
+   verbs:
+   - create
+ - resources:
+   - tokenreviews
+   apiGroups:
+   - authentication.k8s.io
+   verbs:
+   - create
+ - resources:
+   - subjectaccessreviews
+   apiGroups:
+   - authorization.k8s.io
+   verbs:
+   - create

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRole/ceph-csi-nvmeof-nodeplugin-cr
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRole
+ metadata:
+   name: ceph-csi-nvmeof-nodeplugin-cr
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ rules:
+ - resources:
+   - secrets
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+ - resources:
+   - persistentvolumes
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+ - resources:
+   - volumeattachments
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - get
+   - list
+ - resources:
+   - configmaps
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - serviceaccounts
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - serviceaccounts/token
+   apiGroups:
+   - 
+   verbs:
+   - create
+ - resources:
+   - nodes
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - tokenreviews
+   apiGroups:
+   - authentication.k8s.io
+   verbs:
+   - create
+ - resources:
+   - events
+   apiGroups:
+   - 
+   verbs:
+   - list
+   - watch
+   - create
+   - update
+   - patch
+ - resources:
+   - persistentvolumeclaims
+   apiGroups:
+   - 
+   verbs:
+   - get

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRole/ceph-csi-rbd-ctrlplugin-cr
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRole
+ metadata:
+   name: ceph-csi-rbd-ctrlplugin-cr
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ rules:
+ - resources:
+   - secrets
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - persistentvolumes
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+   - watch
+   - create
+   - delete
+   - patch
+   - update
+ - resources:
+   - persistentvolumeclaims
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+   - watch
+   - update
+ - resources:
+   - storageclasses
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - events
+   apiGroups:
+   - 
+   verbs:
+   - list
+   - watch
+   - create
+   - update
+   - patch
+ - resources:
+   - volumeattachments
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+   - patch
+ - resources:
+   - volumeattachments/status
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - patch
+ - resources:
+   - nodes
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - csinodes
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - persistentvolumeclaims/status
+   apiGroups:
+   - 
+   verbs:
+   - patch
+ - resources:
+   - volumesnapshots
+   apiGroups:
+   - snapshot.storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - volumesnapshotclasses
+   apiGroups:
+   - snapshot.storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - volumesnapshotcontents
+   apiGroups:
+   - snapshot.storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+   - patch
+   - update
+ - resources:
+   - volumesnapshotcontents/status
+   apiGroups:
+   - snapshot.storage.k8s.io
+   verbs:
+   - update
+   - patch
+ - resources:
+   - configmaps
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - serviceaccounts
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - serviceaccounts/token
+   apiGroups:
+   - 
+   verbs:
+   - create
+ - resources:
+   - volumegroupsnapshotclasses
+   apiGroups:
+   - groupsnapshot.storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - volumegroupsnapshotcontents
+   apiGroups:
+   - groupsnapshot.storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+   - update
+   - patch
+ - resources:
+   - volumegroupsnapshotcontents/status
+   apiGroups:
+   - groupsnapshot.storage.k8s.io
+   verbs:
+   - update
+   - patch
+ - resources:
+   - volumegroupsnapshotclasses
+   apiGroups:
+   - groupsnapshot.storage.openshift.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - volumegroupsnapshotcontents
+   apiGroups:
+   - groupsnapshot.storage.openshift.io
+   verbs:
+   - get
+   - list
+   - watch
+   - update
+   - patch
+ - resources:
+   - volumegroupsnapshotcontents/status
+   apiGroups:
+   - groupsnapshot.storage.openshift.io
+   verbs:
+   - update
+   - patch
+ - resources:
+   - volumegroupreplicationcontents
+   apiGroups:
+   - replication.storage.openshift.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - volumegroupreplicationclasses
+   apiGroups:
+   - replication.storage.openshift.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - tokenreviews
+   apiGroups:
+   - authentication.k8s.io
+   verbs:
+   - create
+ - resources:
+   - subjectaccessreviews
+   apiGroups:
+   - authorization.k8s.io
+   verbs:
+   - create
+ - resources:
+   - snapshotmetadataservices
+   apiGroups:
+   - cbt.storage.k8s.io
+   verbs:
+   - get
+   - list
+ - resources:
+   - volumeattributesclasses
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRole/ceph-csi-rbd-nodeplugin-cr
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRole
+ metadata:
+   name: ceph-csi-rbd-nodeplugin-cr
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ rules:
+ - resources:
+   - secrets
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - persistentvolumes
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+ - resources:
+   - volumeattachments
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - get
+   - list
+ - resources:
+   - configmaps
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - serviceaccounts
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - serviceaccounts/token
+   apiGroups:
+   - 
+   verbs:
+   - create
+ - resources:
+   - nodes
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - tokenreviews
+   apiGroups:
+   - authentication.k8s.io
+   verbs:
+   - create
+ - resources:
+   - events
+   apiGroups:
+   - 
+   verbs:
+   - list
+   - watch
+   - create
+   - update
+   - patch
+ - resources:
+   - persistentvolumeclaims
+   apiGroups:
+   - 
+   verbs:
+   - get

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRole/cephfs-csi-nodeplugin
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRole
+ metadata:
+   name: cephfs-csi-nodeplugin
+   labels:
+     app.kubernetes.io/created-by: helm
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: rook-ceph
+     app.kubernetes.io/part-of: rook-ceph-operator
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+     operator: rook
+     storage-backend: ceph
+ rules:
+ - resources:
+   - nodes
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - secrets
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - configmaps
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - serviceaccounts
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - serviceaccounts/token
+   apiGroups:
+   - 
+   verbs:
+   - create

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRole/cephfs-external-provisioner-runner
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRole
+ metadata:
+   name: cephfs-external-provisioner-runner
+   labels:
+     app.kubernetes.io/created-by: helm
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: rook-ceph
+     app.kubernetes.io/part-of: rook-ceph-operator
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+     operator: rook
+     storage-backend: ceph
+ rules:
+ - resources:
+   - secrets
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+ - resources:
+   - configmaps
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - nodes
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - csinodes
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - persistentvolumes
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+   - watch
+   - create
+   - update
+   - delete
+   - patch
+ - resources:
+   - persistentvolumeclaims
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+   - watch
+   - patch
+   - update
+ - resources:
+   - storageclasses
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - events
+   apiGroups:
+   - 
+   verbs:
+   - list
+   - watch
+   - create
+   - update
+   - patch
+ - resources:
+   - events
+   apiGroups:
+   - events.k8s.io
+   verbs:
+   - create
+   - patch
+   - update
+ - resources:
+   - volumeattachments
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+   - patch
+ - resources:
+   - volumeattachments/status
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - patch
+ - resources:
+   - persistentvolumeclaims/status
+   apiGroups:
+   - 
+   verbs:
+   - patch
+ - resources:
+   - volumesnapshots
+   apiGroups:
+   - snapshot.storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - volumesnapshotclasses
+   apiGroups:
+   - snapshot.storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - volumesnapshotcontents
+   apiGroups:
+   - snapshot.storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+   - patch
+   - update
+ - resources:
+   - volumesnapshotcontents/status
+   apiGroups:
+   - snapshot.storage.k8s.io
+   verbs:
+   - update
+   - patch
+ - resources:
+   - volumegroupsnapshotclasses
+   apiGroups:
+   - groupsnapshot.storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - volumegroupsnapshotcontents
+   apiGroups:
+   - groupsnapshot.storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+   - update
+   - patch
+ - resources:
+   - volumegroupsnapshotcontents/status
+   apiGroups:
+   - groupsnapshot.storage.k8s.io
+   verbs:
+   - update
+   - patch
+ - resources:
+   - serviceaccounts
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - serviceaccounts/token
+   apiGroups:
+   - 
+   verbs:
+   - create
+ - resources:
+   - tokenreviews
+   apiGroups:
+   - authentication.k8s.io
+   verbs:
+   - create

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRole/rbd-csi-nodeplugin
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRole
+ metadata:
+   name: rbd-csi-nodeplugin
+   labels:
+     app.kubernetes.io/created-by: helm
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: rook-ceph
+     app.kubernetes.io/part-of: rook-ceph-operator
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+     operator: rook
+     storage-backend: ceph
+ rules:
+ - resources:
+   - secrets
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+ - resources:
+   - persistentvolumes
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+ - resources:
+   - volumeattachments
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - get
+   - list
+ - resources:
+   - configmaps
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - serviceaccounts
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - serviceaccounts/token
+   apiGroups:
+   - 
+   verbs:
+   - create
+ - resources:
+   - nodes
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - tokenreviews
+   apiGroups:
+   - authentication.k8s.io
+   verbs:
+   - create

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRole/rbd-external-provisioner-runner
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRole
+ metadata:
+   name: rbd-external-provisioner-runner
+   labels:
+     app.kubernetes.io/created-by: helm
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: rook-ceph
+     app.kubernetes.io/part-of: rook-ceph-operator
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+     operator: rook
+     storage-backend: ceph
+ rules:
+ - resources:
+   - secrets
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - persistentvolumes
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+   - watch
+   - create
+   - update
+   - delete
+   - patch
+ - resources:
+   - persistentvolumeclaims
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+   - watch
+   - update
+ - resources:
+   - storageclasses
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - events
+   apiGroups:
+   - 
+   verbs:
+   - list
+   - watch
+   - create
+   - update
+   - patch
+ - resources:
+   - events
+   apiGroups:
+   - events.k8s.io
+   verbs:
+   - create
+   - patch
+   - update
+ - resources:
+   - volumeattachments
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+   - patch
+ - resources:
+   - volumeattachments/status
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - patch
+ - resources:
+   - nodes
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - csinodes
+   apiGroups:
+   - storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - persistentvolumeclaims/status
+   apiGroups:
+   - 
+   verbs:
+   - patch
+ - resources:
+   - volumesnapshots
+   apiGroups:
+   - snapshot.storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - volumesnapshotclasses
+   apiGroups:
+   - snapshot.storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - volumesnapshotcontents
+   apiGroups:
+   - snapshot.storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+   - patch
+   - update
+ - resources:
+   - volumesnapshotcontents/status
+   apiGroups:
+   - snapshot.storage.k8s.io
+   verbs:
+   - update
+   - patch
+ - resources:
+   - volumegroupsnapshotclasses
+   apiGroups:
+   - groupsnapshot.storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - volumegroupsnapshotcontents
+   apiGroups:
+   - groupsnapshot.storage.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+   - update
+   - patch
+ - resources:
+   - volumegroupsnapshotcontents/status
+   apiGroups:
+   - groupsnapshot.storage.k8s.io
+   verbs:
+   - update
+   - patch
+ - resources:
+   - configmaps
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - serviceaccounts
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - serviceaccounts/token
+   apiGroups:
+   - 
+   verbs:
+   - create
+ - resources:
+   - nodes
+   apiGroups:
+   - 
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - referencegrants
+   apiGroups:
+   - gateway.networking.k8s.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - volumegroupreplicationcontents
+   apiGroups:
+   - replication.storage.openshift.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - volumegroupreplicationclasses
+   apiGroups:
+   - replication.storage.openshift.io
+   verbs:
+   - get
+   - list
+   - watch
+ - resources:
+   - tokenreviews
+   apiGroups:
+   - authentication.k8s.io
+   verbs:
+   - create

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRoleBinding/ceph-csi-cephfs-ctrlplugin-crb
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRoleBinding
+ metadata:
+   name: ceph-csi-cephfs-ctrlplugin-crb
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ roleRef:
+   name: ceph-csi-cephfs-ctrlplugin-cr
+   apiGroup: rbac.authorization.k8s.io
+   kind: ClusterRole
+ subjects:
+ - name: ceph-csi-cephfs-ctrlplugin-sa
+   kind: ServiceAccount
+   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRoleBinding/ceph-csi-cephfs-nodeplugin-crb
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRoleBinding
+ metadata:
+   name: ceph-csi-cephfs-nodeplugin-crb
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ roleRef:
+   name: ceph-csi-cephfs-nodeplugin-cr
+   apiGroup: rbac.authorization.k8s.io
+   kind: ClusterRole
+ subjects:
+ - name: ceph-csi-cephfs-nodeplugin-sa
+   kind: ServiceAccount
+   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRoleBinding/ceph-csi-nfs-ctrlplugin-crb
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRoleBinding
+ metadata:
+   name: ceph-csi-nfs-ctrlplugin-crb
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ roleRef:
+   name: ceph-csi-nfs-ctrlplugin-cr
+   apiGroup: rbac.authorization.k8s.io
+   kind: ClusterRole
+ subjects:
+ - name: ceph-csi-nfs-ctrlplugin-sa
+   kind: ServiceAccount
+   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRoleBinding/ceph-csi-nfs-nodeplugin-crb
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRoleBinding
+ metadata:
+   name: ceph-csi-nfs-nodeplugin-crb
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ roleRef:
+   name: ceph-csi-nfs-nodeplugin-cr
+   apiGroup: rbac.authorization.k8s.io
+   kind: ClusterRole
+ subjects:
+ - name: ceph-csi-nfs-nodeplugin-sa
+   kind: ServiceAccount
+   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRoleBinding/ceph-csi-nvmeof-ctrlplugin-crb
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRoleBinding
+ metadata:
+   name: ceph-csi-nvmeof-ctrlplugin-crb
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ roleRef:
+   name: ceph-csi-nvmeof-ctrlplugin-cr
+   apiGroup: rbac.authorization.k8s.io
+   kind: ClusterRole
+ subjects:
+ - name: ceph-csi-nvmeof-ctrlplugin-sa
+   kind: ServiceAccount
+   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRoleBinding/ceph-csi-nvmeof-nodeplugin-crb
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRoleBinding
+ metadata:
+   name: ceph-csi-nvmeof-nodeplugin-crb
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ roleRef:
+   name: ceph-csi-nvmeof-nodeplugin-cr
+   apiGroup: rbac.authorization.k8s.io
+   kind: ClusterRole
+ subjects:
+ - name: ceph-csi-nvmeof-nodeplugin-sa
+   kind: ServiceAccount
+   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRoleBinding/ceph-csi-rbd-ctrlplugin-crb
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRoleBinding
+ metadata:
+   name: ceph-csi-rbd-ctrlplugin-crb
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ roleRef:
+   name: ceph-csi-rbd-ctrlplugin-cr
+   apiGroup: rbac.authorization.k8s.io
+   kind: ClusterRole
+ subjects:
+ - name: ceph-csi-rbd-ctrlplugin-sa
+   kind: ServiceAccount
+   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRoleBinding/ceph-csi-rbd-nodeplugin-crb
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRoleBinding
+ metadata:
+   name: ceph-csi-rbd-nodeplugin-crb
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ roleRef:
+   name: ceph-csi-rbd-nodeplugin-cr
+   apiGroup: rbac.authorization.k8s.io
+   kind: ClusterRole
+ subjects:
+ - name: ceph-csi-rbd-nodeplugin-sa
+   kind: ServiceAccount
+   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRoleBinding/rbd-csi-nodeplugin
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRoleBinding
+ metadata:
+   name: rbd-csi-nodeplugin
+   labels:
+     app.kubernetes.io/created-by: helm
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: rook-ceph
+     app.kubernetes.io/part-of: rook-ceph-operator
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+     operator: rook
+     storage-backend: ceph
+ roleRef:
+   name: rbd-csi-nodeplugin
+   apiGroup: rbac.authorization.k8s.io
+   kind: ClusterRole
+ subjects:
+ - name: rook-csi-rbd-plugin-sa
+   kind: ServiceAccount
+   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRoleBinding/cephfs-csi-provisioner-role
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRoleBinding
+ metadata:
+   name: cephfs-csi-provisioner-role
+   labels:
+     app.kubernetes.io/created-by: helm
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: rook-ceph
+     app.kubernetes.io/part-of: rook-ceph-operator
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+     operator: rook
+     storage-backend: ceph
+ roleRef:
+   name: cephfs-external-provisioner-runner
+   apiGroup: rbac.authorization.k8s.io
+   kind: ClusterRole
+ subjects:
+ - name: rook-csi-cephfs-provisioner-sa
+   kind: ServiceAccount
+   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRoleBinding/cephfs-csi-nodeplugin-role
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRoleBinding
+ metadata:
+   name: cephfs-csi-nodeplugin-role
+   labels:
+     app.kubernetes.io/created-by: helm
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: rook-ceph
+     app.kubernetes.io/part-of: rook-ceph-operator
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+     operator: rook
+     storage-backend: ceph
+ roleRef:
+   name: cephfs-csi-nodeplugin
+   apiGroup: rbac.authorization.k8s.io
+   kind: ClusterRole
+ subjects:
+ - name: rook-csi-cephfs-plugin-sa
+   kind: ServiceAccount
+   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/ClusterRoleBinding/rbd-csi-provisioner-role
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: ClusterRoleBinding
+ metadata:
+   name: rbd-csi-provisioner-role
+   labels:
+     app.kubernetes.io/created-by: helm
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: rook-ceph
+     app.kubernetes.io/part-of: rook-ceph-operator
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+     operator: rook
+     storage-backend: ceph
+ roleRef:
+   name: rbd-external-provisioner-runner
+   apiGroup: rbac.authorization.k8s.io
+   kind: ClusterRole
+ subjects:
+ - name: rook-csi-rbd-provisioner-sa
+   kind: ServiceAccount
+   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/Role/rook-ceph/ceph-csi-cephfs-ctrlplugin-r
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: Role
+ metadata:
+   name: ceph-csi-cephfs-ctrlplugin-r
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ rules:
+ - resources:
+   - leases
+   apiGroups:
+   - coordination.k8s.io
+   verbs:
+   - get
+   - watch
+   - list
+   - delete
+   - update
+   - create
+ - resources:
+   - csiaddonsnodes
+   apiGroups:
+   - csiaddons.openshift.io
+   verbs:
+   - get
+   - watch
+   - list
+   - create
+   - update
+   - delete
+ - resources:
+   - pods
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - replicasets
+   apiGroups:
+   - apps
+   verbs:
+   - get
+ - resources:
+   - deployments/finalizers
+   - daemonsets/finalizers
+   apiGroups:
+   - apps
+   verbs:
+   - update

@@ (root level) @@
# rbac.authorization.k8s.io/v1/Role/rook-ceph/ceph-csi-cephfs-nodeplugin-r
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: Role
+ metadata:
+   name: ceph-csi-cephfs-nodeplugin-r
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ rules:
+ - resources:
+   - csiaddonsnodes
+   apiGroups:
+   - csiaddons.openshift.io
+   verbs:
+   - get
+   - watch
+   - list
+   - create
+   - update
+   - delete
+ - resources:
+   - pods
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - replicasets
+   apiGroups:
+   - apps
+   verbs:
+   - get
+ - resources:
+   - deployments/finalizers
+   - daemonsets/finalizers
+   apiGroups:
+   - apps
+   verbs:
+   - update

@@ (root level) @@
# rbac.authorization.k8s.io/v1/Role/rook-ceph/ceph-csi-nvmeof-ctrlplugin-r
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: Role
+ metadata:
+   name: ceph-csi-nvmeof-ctrlplugin-r
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ rules:
+ - resources:
+   - leases
+   apiGroups:
+   - coordination.k8s.io
+   verbs:
+   - get
+   - watch
+   - list
+   - delete
+   - update
+   - create
+ - resources:
+   - csiaddonsnodes
+   apiGroups:
+   - csiaddons.openshift.io
+   verbs:
+   - get
+   - watch
+   - list
+   - create
+   - update
+   - delete
+ - resources:
+   - pods
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - replicasets
+   apiGroups:
+   - apps
+   verbs:
+   - get
+ - resources:
+   - deployments/finalizers
+   - daemonsets/finalizers
+   apiGroups:
+   - apps
+   verbs:
+   - update

@@ (root level) @@
# rbac.authorization.k8s.io/v1/Role/rook-ceph/ceph-csi-nvmeof-nodeplugin-r
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: Role
+ metadata:
+   name: ceph-csi-nvmeof-nodeplugin-r
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ rules:
+ - resources:
+   - csiaddonsnodes
+   apiGroups:
+   - csiaddons.openshift.io
+   verbs:
+   - get
+   - watch
+   - list
+   - create
+   - update
+   - delete
+ - resources:
+   - pods
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - replicasets
+   apiGroups:
+   - apps
+   verbs:
+   - get
+ - resources:
+   - deployments/finalizers
+   - daemonsets/finalizers
+   apiGroups:
+   - apps
+   verbs:
+   - update

@@ (root level) @@
# rbac.authorization.k8s.io/v1/Role/rook-ceph/ceph-csi-rbd-ctrlplugin-r
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: Role
+ metadata:
+   name: ceph-csi-rbd-ctrlplugin-r
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ rules:
+ - resources:
+   - leases
+   apiGroups:
+   - coordination.k8s.io
+   verbs:
+   - get
+   - watch
+   - list
+   - delete
+   - update
+   - create
+ - resources:
+   - csiaddonsnodes
+   apiGroups:
+   - csiaddons.openshift.io
+   verbs:
+   - get
+   - watch
+   - list
+   - create
+   - update
+   - delete
+ - resources:
+   - pods
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - replicasets
+   apiGroups:
+   - apps
+   verbs:
+   - get
+ - resources:
+   - deployments/finalizers
+   - daemonsets/finalizers
+   apiGroups:
+   - apps
+   verbs:
+   - update

@@ (root level) @@
# rbac.authorization.k8s.io/v1/Role/rook-ceph/ceph-csi-rbd-nodeplugin-r
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: Role
+ metadata:
+   name: ceph-csi-rbd-nodeplugin-r
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ rules:
+ - resources:
+   - csiaddonsnodes
+   apiGroups:
+   - csiaddons.openshift.io
+   verbs:
+   - get
+   - watch
+   - list
+   - create
+   - update
+   - delete
+ - resources:
+   - pods
+   apiGroups:
+   - 
+   verbs:
+   - get
+ - resources:
+   - replicasets
+   apiGroups:
+   - apps
+   verbs:
+   - get
+ - resources:
+   - deployments/finalizers
+   - daemonsets/finalizers
+   apiGroups:
+   - apps
+   verbs:
+   - update

@@ (root level) @@
# rbac.authorization.k8s.io/v1/Role/rook-ceph/cephfs-external-provisioner-cfg
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: Role
+ metadata:
+   name: cephfs-external-provisioner-cfg
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/created-by: helm
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: rook-ceph
+     app.kubernetes.io/part-of: rook-ceph-operator
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+     operator: rook
+     storage-backend: ceph
+ rules:
+ - resources:
+   - leases
+   apiGroups:
+   - coordination.k8s.io
+   verbs:
+   - get
+   - watch
+   - list
+   - delete
+   - update
+   - create

@@ (root level) @@
# rbac.authorization.k8s.io/v1/Role/rook-ceph/rbd-external-provisioner-cfg
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: Role
+ metadata:
+   name: rbd-external-provisioner-cfg
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/created-by: helm
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: rook-ceph
+     app.kubernetes.io/part-of: rook-ceph-operator
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+     operator: rook
+     storage-backend: ceph
+ rules:
+ - resources:
+   - leases
+   apiGroups:
+   - coordination.k8s.io
+   verbs:
+   - get
+   - watch
+   - list
+   - delete
+   - update
+   - create

@@ (root level) @@
# rbac.authorization.k8s.io/v1/RoleBinding/rook-ceph/ceph-csi-cephfs-ctrlplugin-rb
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: RoleBinding
+ metadata:
+   name: ceph-csi-cephfs-ctrlplugin-rb
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ roleRef:
+   name: ceph-csi-cephfs-ctrlplugin-r
+   apiGroup: rbac.authorization.k8s.io
+   kind: Role
+ subjects:
+ - name: ceph-csi-cephfs-ctrlplugin-sa
+   kind: ServiceAccount
+   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/RoleBinding/rook-ceph/ceph-csi-cephfs-nodeplugin-rb
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: RoleBinding
+ metadata:
+   name: ceph-csi-cephfs-nodeplugin-rb
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ roleRef:
+   name: ceph-csi-cephfs-nodeplugin-r
+   apiGroup: rbac.authorization.k8s.io
+   kind: Role
+ subjects:
+ - name: ceph-csi-cephfs-nodeplugin-sa
+   kind: ServiceAccount
+   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/RoleBinding/rook-ceph/ceph-csi-nvmeof-ctrlplugin-rb
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: RoleBinding
+ metadata:
+   name: ceph-csi-nvmeof-ctrlplugin-rb
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ roleRef:
+   name: ceph-csi-nvmeof-ctrlplugin-r
+   apiGroup: rbac.authorization.k8s.io
+   kind: Role
+ subjects:
+ - name: ceph-csi-nvmeof-ctrlplugin-sa
+   kind: ServiceAccount
+   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/RoleBinding/rook-ceph/ceph-csi-nvmeof-nodeplugin-rb
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: RoleBinding
+ metadata:
+   name: ceph-csi-nvmeof-nodeplugin-rb
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ roleRef:
+   name: ceph-csi-nvmeof-nodeplugin-r
+   apiGroup: rbac.authorization.k8s.io
+   kind: Role
+ subjects:
+ - name: ceph-csi-nvmeof-nodeplugin-sa
+   kind: ServiceAccount
+   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/RoleBinding/rook-ceph/ceph-csi-rbd-ctrlplugin-rb
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: RoleBinding
+ metadata:
+   name: ceph-csi-rbd-ctrlplugin-rb
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ roleRef:
+   name: ceph-csi-rbd-ctrlplugin-r
+   apiGroup: rbac.authorization.k8s.io
+   kind: Role
+ subjects:
+ - name: ceph-csi-rbd-ctrlplugin-sa
+   kind: ServiceAccount
+   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/RoleBinding/rook-ceph/ceph-csi-rbd-nodeplugin-rb
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: RoleBinding
+ metadata:
+   name: ceph-csi-rbd-nodeplugin-rb
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: ceph-csi
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+ roleRef:
+   name: ceph-csi-rbd-nodeplugin-r
+   apiGroup: rbac.authorization.k8s.io
+   kind: Role
+ subjects:
+ - name: ceph-csi-rbd-nodeplugin-sa
+   kind: ServiceAccount
+   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/RoleBinding/rook-ceph/cephfs-csi-provisioner-role-cfg
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: RoleBinding
+ metadata:
+   name: cephfs-csi-provisioner-role-cfg
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/created-by: helm
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: rook-ceph
+     app.kubernetes.io/part-of: rook-ceph-operator
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+     operator: rook
+     storage-backend: ceph
+ roleRef:
+   name: cephfs-external-provisioner-cfg
+   apiGroup: rbac.authorization.k8s.io
+   kind: Role
+ subjects:
+ - name: rook-csi-cephfs-provisioner-sa
+   kind: ServiceAccount
+   namespace: rook-ceph

@@ (root level) @@
# rbac.authorization.k8s.io/v1/RoleBinding/rook-ceph/rbd-csi-provisioner-role-cfg
! + one document added:
+ apiVersion: rbac.authorization.k8s.io/v1
+ kind: RoleBinding
+ metadata:
+   name: rbd-csi-provisioner-role-cfg
+   namespace: rook-ceph
+   labels:
+     app.kubernetes.io/created-by: helm
+     app.kubernetes.io/instance: rook-ceph
+     app.kubernetes.io/managed-by: Helm
+     app.kubernetes.io/name: rook-ceph
+     app.kubernetes.io/part-of: rook-ceph-operator
+     helm.toolkit.fluxcd.io/name: rook-ceph
+     helm.toolkit.fluxcd.io/namespace: rook-ceph
+     operator: rook
+     storage-backend: ceph
+ roleRef:
+   name: rbd-external-provisioner-cfg
+   apiGroup: rbac.authorization.k8s.io
+   kind: Role
+ subjects:
+ - name: rook-csi-rbd-provisioner-sa
+   kind: ServiceAccount
+   namespace: rook-ceph

Diff created by flateWorkflow run

<!-- flate --> <details open><summary>Kustomization diff</summary> ```diff @@ spec.values.controllers.searxng.containers.app.image.tag @@ # helm.toolkit.fluxcd.io/v2/HelmRelease/cortex/searxng ! ± value change - 2026.6.3-5bae05514@sha256:c6dde203961b0b138d17ecbcef31026852a4210926564af48acf58352da38b42 + 2026.5.26-3db8b424a@sha256:9a02b1119e4928f7a4029f6a769e8741359e258792302bac80d2965c39a16493 @@ spec.image @@ # toolhive.stacklok.dev/v1beta1/MCPServer/cortex/mcp-searxng ! ± value change - docker.io/isokoliuk/mcp-searxng:1.1.0 + docker.io/isokoliuk/mcp-searxng:1.0.5 @@ spec.ref.tag @@ # source.toolkit.fluxcd.io/v1/OCIRepository/cortex/toolhive-operator ! ± value change - 0.29.0 + 0.28.3 @@ spec.ref.tag @@ # source.toolkit.fluxcd.io/v1/OCIRepository/cortex/toolhive-operator-crds ! ± value change - 0.29.0 + 0.28.3 @@ spec.dependsOn @@ # kustomize.toolkit.fluxcd.io/v1/Kustomization/rook-ceph/rook-ceph-cluster ! - one list entry removed: - - name: rook-ceph-csi-drivers @@ spec.values.controllers.home-assistant.containers.app.image.tag @@ # helm.toolkit.fluxcd.io/v2/HelmRelease/home-automation/home-assistant ! ± value change - 2026.6.0@sha256:f89628f4623e2b99f368baa6c8ee4e6ca5856f9ad18fe9c36d0af53fe5d5ee29 + 2026.5.4@sha256:42d1bc5e99ed0ae8f49b72b8994e25e1a6b0f1467ba26c1b959f54ca42541ffd @@ spec.values.controllers.home-assistant.containers.codeserver.image.tag @@ # helm.toolkit.fluxcd.io/v2/HelmRelease/home-automation/home-assistant ! ± value change - 4.123.0@sha256:6d46b83ea0687ab1826ec029b6d0e6342bbd55cc5c29b98258463e7faee16d1e + 4.122.1@sha256:31d3bd4039b9d41fde24ae17cc170a769a025df0782bd3bd99f0ea86f8e415a4 @@ spec.values.controllers.zigbee.containers.app.image.tag @@ # helm.toolkit.fluxcd.io/v2/HelmRelease/home-automation/zigbee ! ± value change - 2.11.0@sha256:f1f5195076d771727e9ff3db638de0f54d37969a66f317cd34624a7af5faf364 + 2.10.1@sha256:67c26dcf8346aced02fe1380a6afd1b57268bcef10faae3f6057c13d5d3dfa80 @@ spec.ref.tag @@ # source.toolkit.fluxcd.io/v1/OCIRepository/kube-system/renovate-operator ! ± value change - 4.10.1 + 4.9.0 @@ spec.values.controllers.prowlarr.containers.app.image.tag @@ # helm.toolkit.fluxcd.io/v2/HelmRelease/media/prowlarr ! ± value change - 2.4.0.5391@sha256:91af7cbc8e357dede960033c9ecfb3a65e145d90d4e495e13adb2fbc6a546807 + 2.3.7.5365@sha256:b9557d772c974901aed9285189d904b613f1f07750fca930eecfe78544bd3d48 @@ spec.values.controllers.app.containers.app.image.tag @@ # helm.toolkit.fluxcd.io/v2/HelmRelease/media/seerr ! ± value change - v3.3.0@sha256:c92d2dc117f62185e7bcb88cd56efd374ea79210eaf433275449e8d5988eb5a8 + v3.2.0@sha256:c4cbd5121236ac2f70a843a0b920b68a27976be57917555f1c45b08a1e6b2aad @@ spec.values.provider.webhook.image.tag @@ # helm.toolkit.fluxcd.io/v2/HelmRelease/network/external-dns-unifi ! ± value change - v0.9.0 + v0.8.2 @@ spec.ref.tag @@ # source.toolkit.fluxcd.io/v1/OCIRepository/rook-ceph/rook-ceph-cluster ! ± value change - v1.20.0 + v1.19.6 @@ spec.upgrade @@ # helm.toolkit.fluxcd.io/v2/HelmRelease/rook-ceph/rook-ceph-cluster ! - one map entry removed: - timeout: 30m @@ spec.values @@ # helm.toolkit.fluxcd.io/v2/HelmRelease/rook-ceph/rook-ceph-cluster ! - one map entry removed: - cephImage: - repository: quay.io/ceph/ceph - tag: v20.2.1 @@ spec.values.csi @@ # helm.toolkit.fluxcd.io/v2/HelmRelease/rook-ceph/rook-ceph ! + three map entries added: + cephFSKernelMountOptions: ms_mode=prefer-crc + enableLiveness: true + provisionerNodeAffinity: "kubernetes.io/hostname=talos-w-01,talos-w-02,talos-gpu-01" @@ spec.ref.tag @@ # source.toolkit.fluxcd.io/v1/OCIRepository/rook-ceph/rook-ceph ! ± value change - v1.20.0 + v1.19.6 @@ data @@ # v1/ConfigMap/rook-ceph/rook-ceph-operator-config ! + one map entry added: + ROOK_CSI_PROVISIONER_IMAGE: "registry.k8s.io/sig-storage/csi-provisioner:v6.2.0" @@ spec.values.controllers.pocket-id.containers.app.image.tag @@ # helm.toolkit.fluxcd.io/v2/HelmRelease/security/pocket-id ! ± value change - v2.7.0 + v2.8.0 @@ (root level) @@ # kustomize.toolkit.fluxcd.io/v1/Kustomization/rook-ceph/rook-ceph-csi-drivers ! - one document removed: - apiVersion: kustomize.toolkit.fluxcd.io/v1 - kind: Kustomization - metadata: - name: rook-ceph-csi-drivers - namespace: rook-ceph - labels: - kustomize.toolkit.fluxcd.io/name: artemis-cluster - kustomize.toolkit.fluxcd.io/namespace: flux-system - spec: - commonMetadata: - labels: - app.kubernetes.io/name: rook-ceph-csi-drivers - deletionPolicy: WaitForTermination - dependsOn: - - name: rook-ceph-operator - interval: 1h - patches: - - patch: | - apiVersion: helm.toolkit.fluxcd.io/v2 - kind: HelmRelease - metadata: - name: _ - spec: - install: - crds: CreateReplace - strategy: - name: RetryOnFailure - rollback: - cleanupOnFail: true - recreate: true - upgrade: - cleanupOnFail: true - crds: CreateReplace - strategy: - name: RemediateOnFailure - remediation: - remediateLastFailure: true - retries: 2 - target: - kind: HelmRelease - group: helm.toolkit.fluxcd.io - path: ./kubernetes/apps/rook-ceph/rook-ceph/csi-drivers - prune: true - retryInterval: 1m - sourceRef: - name: flux-system - kind: GitRepository - namespace: flux-system - targetNamespace: rook-ceph - timeout: 10m - wait: true @@ (root level) @@ # source.toolkit.fluxcd.io/v1/HelmRepository/rook-ceph/ceph-csi-operator ! - one document removed: - apiVersion: source.toolkit.fluxcd.io/v1 - kind: HelmRepository - metadata: - name: ceph-csi-operator - namespace: rook-ceph - labels: - app.kubernetes.io/name: rook-ceph-csi-drivers - kustomize.toolkit.fluxcd.io/name: rook-ceph-csi-drivers - kustomize.toolkit.fluxcd.io/namespace: rook-ceph - spec: - url: "https://ceph.github.io/ceph-csi-operator" - interval: 1h @@ (root level) @@ # helm.toolkit.fluxcd.io/v2/HelmRelease/rook-ceph/ceph-csi-drivers ! - one document removed: - apiVersion: helm.toolkit.fluxcd.io/v2 - kind: HelmRelease - metadata: - name: ceph-csi-drivers - namespace: rook-ceph - labels: - app.kubernetes.io/name: rook-ceph-csi-drivers - kustomize.toolkit.fluxcd.io/name: rook-ceph-csi-drivers - kustomize.toolkit.fluxcd.io/namespace: rook-ceph - spec: - chart: - spec: - version: "1.0.1" - chart: ceph-csi-drivers - sourceRef: - name: ceph-csi-operator - kind: HelmRepository - namespace: rook-ceph - install: - crds: CreateReplace - strategy: - name: RetryOnFailure - interval: 1h - rollback: - cleanupOnFail: true - recreate: true - upgrade: - cleanupOnFail: true - crds: CreateReplace - remediation: - remediateLastFailure: true - retries: 2 - strategy: - name: RemediateOnFailure - values: - cephConnections: [] - clientProfiles: [] - operatorConfig: - driverSpecDefaults: - controllerPlugin: - affinity: - nodeAffinity: - requiredDuringSchedulingIgnoredDuringExecution: - nodeSelectorTerms: - - matchExpressions: - - key: kubernetes.io/hostname - operator: In - values: - - talos-w-01 - - talos-w-02 - - talos-gpu-01 - kernelMountOptions: - ms_mode: prefer-crc ``` </details> <details open><summary>HelmRelease diff</summary> ```diff @@ spec.template.spec.containers.app.image @@ # apps/v1/Deployment/cortex/searxng ! ± value change - ghcr.io/searxng/searxng:2026.6.3-5bae05514@sha256:c6dde203961b0b138d17ecbcef31026852a4210926564af48acf58352da38b42 + ghcr.io/searxng/searxng:2026.5.26-3db8b424a@sha256:9a02b1119e4928f7a4029f6a769e8741359e258792302bac80d2965c39a16493 @@ rules @@ # rbac.authorization.k8s.io/v1/ClusterRole/toolhive-operator-manager-role ! - three list entries removed: - - resources: - - customresourcedefinitions - apiGroups: - - apiextensions.k8s.io - verbs: - - get - - list - - watch - - resources: - - customresourcedefinitions/status - apiGroups: - - apiextensions.k8s.io - verbs: - - patch - - update - - resources: - - "*" - apiGroups: - - toolhive.stacklok.dev - verbs: - - get - - list - - update @@ spec.template.spec.containers.manager.env @@ # apps/v1/Deployment/cortex/toolhive-operator ! - one list entry removed: - - name: TOOLHIVE_ENABLE_STORAGE_VERSION_MIGRATOR - value: "false" @@ spec.template.spec.containers.manager.env.TOOLHIVE_RUNNER_IMAGE.value @@ # apps/v1/Deployment/cortex/toolhive-operator ! ± value change - ghcr.io/stacklok/toolhive/proxyrunner:v0.29.0 + ghcr.io/stacklok/toolhive/proxyrunner:v0.28.3 @@ spec.template.spec.containers.manager.env.VMCP_IMAGE.value @@ # apps/v1/Deployment/cortex/toolhive-operator ! ± value change - ghcr.io/stacklok/toolhive/vmcp:v0.29.0 + ghcr.io/stacklok/toolhive/vmcp:v0.28.3 @@ spec.template.spec.containers.manager.image @@ # apps/v1/Deployment/cortex/toolhive-operator ! ± value change - ghcr.io/stacklok/toolhive/operator:v0.29.0 + ghcr.io/stacklok/toolhive/operator:v0.28.3 @@ spec.template.spec.containers.app.image @@ # apps/v1/Deployment/home-automation/home-assistant ! ± value change - ghcr.io/home-operations/home-assistant:2026.6.0@sha256:f89628f4623e2b99f368baa6c8ee4e6ca5856f9ad18fe9c36d0af53fe5d5ee29 + ghcr.io/home-operations/home-assistant:2026.5.4@sha256:42d1bc5e99ed0ae8f49b72b8994e25e1a6b0f1467ba26c1b959f54ca42541ffd @@ spec.template.spec.containers.codeserver.image @@ # apps/v1/Deployment/home-automation/home-assistant ! ± value change - ghcr.io/coder/code-server:4.123.0@sha256:6d46b83ea0687ab1826ec029b6d0e6342bbd55cc5c29b98258463e7faee16d1e + ghcr.io/coder/code-server:4.122.1@sha256:31d3bd4039b9d41fde24ae17cc170a769a025df0782bd3bd99f0ea86f8e415a4 @@ spec.template.spec.containers.app.image @@ # apps/v1/Deployment/home-automation/zigbee ! ± value change - ghcr.io/koenkk/zigbee2mqtt:2.11.0@sha256:f1f5195076d771727e9ff3db638de0f54d37969a66f317cd34624a7af5faf364 + ghcr.io/koenkk/zigbee2mqtt:2.10.1@sha256:67c26dcf8346aced02fe1380a6afd1b57268bcef10faae3f6057c13d5d3dfa80 @@ spec.template.spec.containers.renovate-operator.image @@ # apps/v1/Deployment/kube-system/renovate-operator ! ± value change - ghcr.io/mogenius/renovate-operator:4.10.1 + ghcr.io/mogenius/renovate-operator:4.9.0 @@ data.renovatejob.yaml @@ # v1/ConfigMap/kube-system/renovate-operator-crd ! ± value change in multiline text (no inserts, one deletion) --- apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: [3137 lines unchanged)] required: - name type: object type: array - githubAppReference: - description: |- - Reference to a Github App for authentication, this will automatically mount a secret with - RENOVATE_TOKEN - properties: - appIdSecretKey: - type: string - installationIdSecretKey: - type: string - pemSecretKey: - type: string - secretName: - type: string - required: - - appIdSecretKey - - installationIdSecretKey - - pemSecretKey - - secretName - type: object image: description: Renovate Docker image to use type: string imagePullSecrets: [1220 lines unchanged)] served: true storage: true subresources: status: {} @@ spec.template.spec.containers.app.image @@ # apps/v1/Deployment/media/prowlarr ! ± value change - ghcr.io/home-operations/prowlarr:2.4.0.5391@sha256:91af7cbc8e357dede960033c9ecfb3a65e145d90d4e495e13adb2fbc6a546807 + ghcr.io/home-operations/prowlarr:2.3.7.5365@sha256:b9557d772c974901aed9285189d904b613f1f07750fca930eecfe78544bd3d48 @@ spec.template.spec.containers.app.image @@ # apps/v1/Deployment/media/seerr ! ± value change - ghcr.io/seerr-team/seerr:v3.3.0@sha256:c92d2dc117f62185e7bcb88cd56efd374ea79210eaf433275449e8d5988eb5a8 + ghcr.io/seerr-team/seerr:v3.2.0@sha256:c4cbd5121236ac2f70a843a0b920b68a27976be57917555f1c45b08a1e6b2aad @@ spec.template.spec.containers.webhook.image @@ # apps/v1/Deployment/network/external-dns-unifi ! ± value change - ghcr.io/kashalls/external-dns-unifi-webhook:v0.9.0 + ghcr.io/kashalls/external-dns-unifi-webhook:v0.8.2 @@ data @@ # v1/ConfigMap/rook-ceph/rook-ceph-operator-config ! - two map entries removed: - ROOK_CEPH_MON_RUN_AS_ROOT: "false" - ROOK_DELETE_UNUSED_CRUSH_RULES: "true" ! + 45 map entries added: + CSI_CEPHFS_ATTACH_REQUIRED: "true" + CSI_CEPHFS_FSGROUPPOLICY: File + CSI_CEPHFS_KERNEL_MOUNT_OPTIONS: ms_mode=prefer-crc + CSI_CEPHFS_PLUGIN_RESOURCE: | + - name : driver-registrar + resource: + requests: + memory: 128Mi + cpu: 50m + limits: + memory: 256Mi + - name : csi-cephfsplugin + resource: + requests: + memory: 512Mi + cpu: 250m + limits: + memory: 1Gi + - name : liveness-prometheus + resource: + requests: + memory: 128Mi + cpu: 50m + limits: + memory: 256Mi + + CSI_CEPHFS_PROVISIONER_RESOURCE: | + - name : csi-provisioner + resource: + requests: + memory: 128Mi + cpu: 100m + limits: + memory: 256Mi + - name : csi-resizer + resource: + requests: + memory: 128Mi + cpu: 100m + limits: + memory: 256Mi + - name : csi-attacher + resource: + requests: + memory: 128Mi + cpu: 100m + limits: + memory: 256Mi + - name : csi-snapshotter + resource: + requests: + memory: 128Mi + cpu: 100m + limits: + memory: 256Mi + - name : csi-cephfsplugin + resource: + requests: + memory: 512Mi + cpu: 250m + limits: + memory: 1Gi + - name : liveness-prometheus + resource: + requests: + memory: 128Mi + cpu: 50m + limits: + memory: 256Mi + + CSI_ENABLE_CEPHFS_SNAPSHOTTER: "true" + CSI_ENABLE_CROSS_NAMESPACE_VOLUME_DATA_SOURCE: "false" + CSI_ENABLE_CSIADDONS: "false" + CSI_ENABLE_ENCRYPTION: "false" + CSI_ENABLE_HOST_NETWORK: "true" + CSI_ENABLE_LIVENESS: "true" + CSI_ENABLE_METADATA: "false" + CSI_ENABLE_NFS_SNAPSHOTTER: "true" + CSI_ENABLE_OMAP_GENERATOR: "false" + CSI_ENABLE_RBD_SNAPSHOTTER: "true" + CSI_ENABLE_TOPOLOGY: "false" + CSI_ENABLE_VOLUME_GROUP_SNAPSHOT: "true" + CSI_FORCE_CEPHFS_KERNEL_CLIENT: "true" + CSI_GRPC_TIMEOUT_SECONDS: "150" + CSI_NFS_ATTACH_REQUIRED: "true" + CSI_NFS_FSGROUPPOLICY: File + CSI_NFS_PLUGIN_RESOURCE: | + - name : driver-registrar + resource: + requests: + memory: 128Mi + cpu: 50m + limits: + memory: 256Mi + - name : csi-nfsplugin + resource: + requests: + memory: 512Mi + cpu: 250m + limits: + memory: 1Gi + + CSI_NFS_PROVISIONER_RESOURCE: | + - name : csi-provisioner + resource: + requests: + memory: 128Mi + cpu: 100m + limits: + memory: 256Mi + - name : csi-nfsplugin + resource: + requests: + memory: 512Mi + cpu: 250m + limits: + memory: 1Gi + - name : csi-attacher + resource: + requests: + memory: 512Mi + cpu: 250m + limits: + memory: 1Gi + + CSI_PLUGIN_ENABLE_SELINUX_HOST_MOUNT: "false" + CSI_PLUGIN_PRIORITY_CLASSNAME: system-node-critical + CSI_PROVISIONER_NODE_AFFINITY: "kubernetes.io/hostname=talos-w-01,talos-w-02,talos-gpu-01" + CSI_PROVISIONER_PRIORITY_CLASSNAME: system-cluster-critical + CSI_PROVISIONER_REPLICAS: "2" + CSI_RBD_ATTACH_REQUIRED: "true" + CSI_RBD_FSGROUPPOLICY: File + CSI_RBD_PLUGIN_RESOURCE: | + - name : driver-registrar + resource: + requests: + memory: 128Mi + cpu: 50m + limits: + memory: 256Mi + - name : csi-rbdplugin + resource: + requests: + memory: 512Mi + cpu: 250m + limits: + memory: 1Gi + - name : liveness-prometheus + resource: + requests: + memory: 128Mi + cpu: 50m + limits: + memory: 256Mi + + CSI_RBD_PROVISIONER_RESOURCE: | + - name : csi-provisioner + resource: + requests: + memory: 128Mi + cpu: 100m + limits: + memory: 256Mi + - name : csi-resizer + resource: + requests: + memory: 128Mi + cpu: 100m + limits: + memory: 256Mi + - name : csi-attacher + resource: + requests: + memory: 128Mi + cpu: 100m + limits: + memory: 256Mi + - name : csi-snapshotter + resource: + requests: + memory: 128Mi + cpu: 100m + limits: + memory: 256Mi + - name : csi-rbdplugin + resource: + requests: + memory: 512Mi + limits: + memory: 1Gi + - name : csi-omap-generator + resource: + requests: + memory: 512Mi + cpu: 250m + limits: + memory: 1Gi + - name : liveness-prometheus + resource: + requests: + memory: 128Mi + cpu: 50m + limits: + memory: 256Mi + + ROOK_CSI_ATTACHER_IMAGE: "registry.k8s.io/sig-storage/csi-attacher:v4.11.0" + ROOK_CSI_CEPH_IMAGE: "quay.io/cephcsi/cephcsi:v3.16.2" + ROOK_CSI_DISABLE_DRIVER: "false" + ROOK_CSI_ENABLE_CEPHFS: "true" + ROOK_CSI_ENABLE_NFS: "false" + ROOK_CSI_ENABLE_RBD: "true" + ROOK_CSI_IMAGE_PULL_POLICY: IfNotPresent + ROOK_CSI_PROVISIONER_IMAGE: "registry.k8s.io/sig-storage/csi-provisioner:v6.1.1" + ROOK_CSI_REGISTRAR_IMAGE: "registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.16.0" + ROOK_CSI_RESIZER_IMAGE: "registry.k8s.io/sig-storage/csi-resizer:v2.1.0" + ROOK_CSI_SNAPSHOTTER_IMAGE: "registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0" + ROOK_CSIADDONS_IMAGE: "quay.io/csiaddons/k8s-sidecar:v0.14.0" + ROOK_USE_CSI_OPERATOR: "true" @@ rules @@ # rbac.authorization.k8s.io/v1/ClusterRole/rook-ceph-global ! - three list entries removed: - - resources: - - cephclients - - cephclusters - - cephblockpools - - cephfilesystems - - cephnfses - - cephnvmeofgateways - - cephobjectstores - - cephobjectstoreusers - - cephobjectstoreaccounts - - cephobjectrealms - - cephobjectzonegroups - - cephobjectzones - - cephbuckettopics - - cephbucketnotifications - - cephrbdmirrors - - cephfilesystemmirrors - - cephfilesystemsubvolumegroups - - cephblockpoolradosnamespaces - - cephcosidrivers - apiGroups: - - ceph.rook.io - verbs: - - get - - list - - watch - - update - - resources: - - cephclients/status - - cephclusters/status - - cephblockpools/status - - cephfilesystems/status - - cephnfses/status - - cephnvmeofgateways/status - - cephobjectstores/status - - cephobjectstoreusers/status - - cephobjectstoreaccounts/status - - cephobjectrealms/status - - cephobjectzonegroups/status - - cephobjectzones/status - - cephbuckettopics/status - - cephbucketnotifications/status - - cephrbdmirrors/status - - cephfilesystemmirrors/status - - cephfilesystemsubvolumegroups/status - - cephblockpoolradosnamespaces/status - apiGroups: - - ceph.rook.io - verbs: - - update - - resources: - - cephclients/finalizers - - cephclusters/finalizers - - cephblockpools/finalizers - - cephfilesystems/finalizers - - cephnfses/finalizers - - cephnvmeofgateways/finalizers - - cephobjectstores/finalizers - - cephobjectstoreusers/finalizers - - cephobjectstoreaccounts/finalizers - - cephobjectrealms/finalizers - - cephobjectzonegroups/finalizers - - cephobjectzones/finalizers - - cephbuckettopics/finalizers - - cephbucketnotifications/finalizers - - cephrbdmirrors/finalizers - - cephfilesystemmirrors/finalizers - - cephfilesystemsubvolumegroups/finalizers - - cephblockpoolradosnamespaces/finalizers - apiGroups: - - ceph.rook.io - verbs: - - update ! + three list entries added: + - resources: + - cephclients + - cephclusters + - cephblockpools + - cephfilesystems + - cephnfses + - cephnvmeofgateways + - cephobjectstores + - cephobjectstoreusers + - cephobjectrealms + - cephobjectzonegroups + - cephobjectzones + - cephbuckettopics + - cephbucketnotifications + - cephrbdmirrors + - cephfilesystemmirrors + - cephfilesystemsubvolumegroups + - cephblockpoolradosnamespaces + - cephcosidrivers + apiGroups: + - ceph.rook.io + verbs: + - get + - list + - watch + - update + - resources: + - cephclients/status + - cephclusters/status + - cephblockpools/status + - cephfilesystems/status + - cephnfses/status + - cephnvmeofgateways/status + - cephobjectstores/status + - cephobjectstoreusers/status + - cephobjectrealms/status + - cephobjectzonegroups/status + - cephobjectzones/status + - cephbuckettopics/status + - cephbucketnotifications/status + - cephrbdmirrors/status + - cephfilesystemmirrors/status + - cephfilesystemsubvolumegroups/status + - cephblockpoolradosnamespaces/status + apiGroups: + - ceph.rook.io + verbs: + - update + - resources: + - cephclients/finalizers + - cephclusters/finalizers + - cephblockpools/finalizers + - cephfilesystems/finalizers + - cephnfses/finalizers + - cephnvmeofgateways/finalizers + - cephobjectstores/finalizers + - cephobjectstoreusers/finalizers + - cephobjectrealms/finalizers + - cephobjectzonegroups/finalizers + - cephobjectzones/finalizers + - cephbuckettopics/finalizers + - cephbucketnotifications/finalizers + - cephrbdmirrors/finalizers + - cephfilesystemmirrors/finalizers + - cephfilesystemsubvolumegroups/finalizers + - cephblockpoolradosnamespaces/finalizers + apiGroups: + - ceph.rook.io + verbs: + - update @@ subjects @@ # rbac.authorization.k8s.io/v1/ClusterRoleBinding/ceph-csi-manager-rolebinding ! - one list entry removed: - - name: ceph-csi - kind: ServiceAccount - namespace: rook-ceph ! + one list entry added: + - name: ceph-csi-controller-manager + kind: ServiceAccount + namespace: rook-ceph @@ subjects @@ # rbac.authorization.k8s.io/v1/ClusterRoleBinding/ceph-csi-metrics-auth-rolebinding ! - one list entry removed: - - name: ceph-csi - kind: ServiceAccount - namespace: rook-ceph ! + one list entry added: + - name: ceph-csi-controller-manager + kind: ServiceAccount + namespace: rook-ceph @@ subjects @@ # rbac.authorization.k8s.io/v1/RoleBinding/rook-ceph/ceph-csi-leader-election-rolebinding ! - one list entry removed: - - name: ceph-csi - kind: ServiceAccount - namespace: rook-ceph ! + one list entry added: + - name: ceph-csi-controller-manager + kind: ServiceAccount + namespace: rook-ceph @@ spec.template.spec @@ # apps/v1/Deployment/rook-ceph/ceph-csi-controller-manager ! - four map entries removed: - nodeSelector: {} - priorityClassName: null - tolerations: [] - topologySpreadConstraints: [] @@ spec.template.spec.containers.manager.env.CSI_SERVICE_ACCOUNT_PREFIX.value @@ # apps/v1/Deployment/rook-ceph/ceph-csi-controller-manager ! ± value change - + ceph-csi- @@ spec.template.spec.containers.manager.image @@ # apps/v1/Deployment/rook-ceph/ceph-csi-controller-manager ! ± value change - quay.io/cephcsi/ceph-csi-operator:v1.0.1 + quay.io/cephcsi/ceph-csi-operator:v0.6.0 @@ spec.template.spec.serviceAccountName @@ # apps/v1/Deployment/rook-ceph/ceph-csi-controller-manager ! ± value change - ceph-csi + ceph-csi-controller-manager @@ spec.template.spec.containers.rook-ceph-operator.image @@ # apps/v1/Deployment/rook-ceph/rook-ceph-operator ! ± value change - ghcr.io/rook/ceph:v1.20.0 + ghcr.io/rook/ceph:v1.19.6 @@ spec.template.spec.containers.rook-ceph-tools.image @@ # apps/v1/Deployment/rook-ceph/rook-ceph-tools ! ± value change - quay.io/ceph/ceph:v20.2.1 + quay.io/ceph/ceph:v19.2.3 @@ spec.cephVersion.image @@ # ceph.rook.io/v1/CephCluster/rook-ceph/rook-ceph ! ± value change - quay.io/ceph/ceph:v20.2.1 + quay.io/ceph/ceph:v19.2.3 @@ spec.template.spec.containers.app.image @@ # apps/v1/Deployment/security/pocket-id ! ± value change - ghcr.io/pocket-id/pocket-id:v2.7.0 + ghcr.io/pocket-id/pocket-id:v2.8.0 @@ (root level) @@ # v1/ServiceAccount/rook-ceph/cephfs-csi-ceph-com-ctrlplugin-sa ! - one document removed: - apiVersion: v1 - kind: ServiceAccount - metadata: - name: cephfs-csi-ceph-com-ctrlplugin-sa - namespace: rook-ceph - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph @@ (root level) @@ # v1/ServiceAccount/rook-ceph/cephfs-csi-ceph-com-nodeplugin-sa ! - one document removed: - apiVersion: v1 - kind: ServiceAccount - metadata: - name: cephfs-csi-ceph-com-nodeplugin-sa - namespace: rook-ceph - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph @@ (root level) @@ # v1/ServiceAccount/rook-ceph/nfs-csi-ceph-com-ctrlplugin-sa ! - one document removed: - apiVersion: v1 - kind: ServiceAccount - metadata: - name: nfs-csi-ceph-com-ctrlplugin-sa - namespace: rook-ceph - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph @@ (root level) @@ # v1/ServiceAccount/rook-ceph/nfs-csi-ceph-com-nodeplugin-sa ! - one document removed: - apiVersion: v1 - kind: ServiceAccount - metadata: - name: nfs-csi-ceph-com-nodeplugin-sa - namespace: rook-ceph - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph @@ (root level) @@ # v1/ServiceAccount/rook-ceph/nvmeof-csi-ceph-com-ctrlplugin-sa ! - one document removed: - apiVersion: v1 - kind: ServiceAccount - metadata: - name: nvmeof-csi-ceph-com-ctrlplugin-sa - namespace: rook-ceph - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph @@ (root level) @@ # v1/ServiceAccount/rook-ceph/nvmeof-csi-ceph-com-nodeplugin-sa ! - one document removed: - apiVersion: v1 - kind: ServiceAccount - metadata: - name: nvmeof-csi-ceph-com-nodeplugin-sa - namespace: rook-ceph - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph @@ (root level) @@ # v1/ServiceAccount/rook-ceph/rbd-csi-ceph-com-ctrlplugin-sa ! - one document removed: - apiVersion: v1 - kind: ServiceAccount - metadata: - name: rbd-csi-ceph-com-ctrlplugin-sa - namespace: rook-ceph - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph @@ (root level) @@ # v1/ServiceAccount/rook-ceph/rbd-csi-ceph-com-nodeplugin-sa ! - one document removed: - apiVersion: v1 - kind: ServiceAccount - metadata: - name: rbd-csi-ceph-com-nodeplugin-sa - namespace: rook-ceph - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRole/cephfs-csi-ceph-com-ctrlplugin-cr ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: cephfs-csi-ceph-com-ctrlplugin-cr - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - rules: - - resources: - - secrets - apiGroups: - - - verbs: - - get - - list - - watch - - resources: - - configmaps - apiGroups: - - - verbs: - - get - - resources: - - nodes - apiGroups: - - - verbs: - - get - - list - - watch - - resources: - - csinodes - apiGroups: - - storage.k8s.io - verbs: - - get - - list - - watch - - resources: - - persistentvolumes - apiGroups: - - - verbs: - - get - - list - - watch - - create - - delete - - patch - - update - - resources: - - persistentvolumeclaims - apiGroups: - - - verbs: - - get - - list - - watch - - patch - - update - - resources: - - storageclasses - apiGroups: - - storage.k8s.io - verbs: - - get - - list - - watch - - resources: - - events - apiGroups: - - - verbs: - - list - - watch - - create - - update - - patch - - resources: - - volumeattachments - apiGroups: - - storage.k8s.io - verbs: - - get - - list - - watch - - patch - - resources: - - volumeattachments/status - apiGroups: - - storage.k8s.io - verbs: - - patch - - resources: - - persistentvolumeclaims/status - apiGroups: - - - verbs: - - patch - - resources: - - volumesnapshots - apiGroups: - - snapshot.storage.k8s.io - verbs: - - get - - list - - resources: - - volumesnapshotclasses - apiGroups: - - snapshot.storage.k8s.io - verbs: - - get - - list - - watch - - resources: - - volumesnapshotcontents - apiGroups: - - snapshot.storage.k8s.io - verbs: - - get - - list - - watch - - patch - - update - - resources: - - volumesnapshotcontents/status - apiGroups: - - snapshot.storage.k8s.io - verbs: - - update - - patch - - resources: - - volumegroupsnapshotclasses - apiGroups: - - groupsnapshot.storage.k8s.io - verbs: - - get - - list - - watch - - resources: - - volumegroupsnapshotcontents - apiGroups: - - groupsnapshot.storage.k8s.io - verbs: - - get - - list - - watch - - update - - patch - - resources: - - volumegroupsnapshotcontents/status - apiGroups: - - groupsnapshot.storage.k8s.io - verbs: - - update - - patch - - resources: - - volumegroupsnapshotclasses - apiGroups: - - groupsnapshot.storage.openshift.io - verbs: - - get - - list - - watch - - resources: - - volumegroupsnapshotcontents - apiGroups: - - groupsnapshot.storage.openshift.io - verbs: - - get - - list - - watch - - update - - patch - - resources: - - volumegroupsnapshotcontents/status - apiGroups: - - groupsnapshot.storage.openshift.io - verbs: - - update - - patch - - resources: - - volumegroupreplicationcontents - apiGroups: - - replication.storage.openshift.io - verbs: - - get - - list - - watch - - resources: - - volumegroupreplicationclasses - apiGroups: - - replication.storage.openshift.io - verbs: - - get - - resources: - - serviceaccounts - apiGroups: - - - verbs: - - get - - resources: - - serviceaccounts/token - apiGroups: - - - verbs: - - create - - resources: - - tokenreviews - apiGroups: - - authentication.k8s.io - verbs: - - create @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRole/cephfs-csi-ceph-com-nodeplugin-cr ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: cephfs-csi-ceph-com-nodeplugin-cr - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - rules: - - resources: - - nodes - apiGroups: - - - verbs: - - get - - resources: - - secrets - apiGroups: - - - verbs: - - get - - list - - watch - - resources: - - configmaps - apiGroups: - - - verbs: - - get - - resources: - - serviceaccounts - apiGroups: - - - verbs: - - get - - resources: - - serviceaccounts/token - apiGroups: - - - verbs: - - create - - resources: - - events - apiGroups: - - - verbs: - - list - - watch - - create - - update - - patch - - resources: - - persistentvolumes - - persistentvolumeclaims - apiGroups: - - - verbs: - - get - - resources: - - tokenreviews - apiGroups: - - authentication.k8s.io - verbs: - - create @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRole/nfs-csi-ceph-com-ctrlplugin-cr ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: nfs-csi-ceph-com-ctrlplugin-cr - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - rules: - - resources: - - persistentvolumes - apiGroups: - - - verbs: - - get - - list - - watch - - create - - update - - delete - - patch - - resources: - - persistentvolumeclaims - apiGroups: - - - verbs: - - get - - list - - watch - - patch - - update - - resources: - - storageclasses - apiGroups: - - storage.k8s.io - verbs: - - get - - list - - watch - - resources: - - events - apiGroups: - - - verbs: - - get - - list - - watch - - create - - update - - patch - - resources: - - csinodes - apiGroups: - - storage.k8s.io - verbs: - - get - - list - - watch - - resources: - - nodes - apiGroups: - - - verbs: - - get - - list - - watch - - resources: - - leases - apiGroups: - - coordination.k8s.io - verbs: - - get - - list - - watch - - create - - update - - patch - - resources: - - secrets - apiGroups: - - - verbs: - - get - - resources: - - volumesnapshotclasses - apiGroups: - - snapshot.storage.k8s.io - verbs: - - get - - list - - watch - - resources: - - volumesnapshotcontents - apiGroups: - - snapshot.storage.k8s.io - verbs: - - get - - list - - watch - - update - - patch - - resources: - - volumesnapshotcontents/status - apiGroups: - - snapshot.storage.k8s.io - verbs: - - update - - patch - - resources: - - volumesnapshots - apiGroups: - - snapshot.storage.k8s.io - verbs: - - get - - list - - resources: - - persistentvolumeclaims/status - apiGroups: - - - verbs: - - patch - - resources: - - volumeattachments - apiGroups: - - storage.k8s.io - verbs: - - get - - list - - watch - - patch - - resources: - - volumeattachments/status - apiGroups: - - storage.k8s.io - verbs: - - patch @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRole/nfs-csi-ceph-com-nodeplugin-cr ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: nfs-csi-ceph-com-nodeplugin-cr - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - rules: - - resources: - - nodes - apiGroups: - - - verbs: - - get @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRole/nvmeof-csi-ceph-com-ctrlplugin-cr ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: nvmeof-csi-ceph-com-ctrlplugin-cr - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - rules: - - resources: - - secrets - apiGroups: - - - verbs: - - get - - list - - watch - - resources: - - persistentvolumes - apiGroups: - - - verbs: - - get - - list - - watch - - create - - delete - - patch - - update - - resources: - - persistentvolumeclaims - apiGroups: - - - verbs: - - get - - list - - watch - - update - - resources: - - storageclasses - apiGroups: - - storage.k8s.io - verbs: - - get - - list - - watch - - resources: - - events - apiGroups: - - - verbs: - - list - - watch - - create - - update - - patch - - resources: - - volumeattachments - apiGroups: - - storage.k8s.io - verbs: - - get - - list - - watch - - patch - - resources: - - volumeattachments/status - apiGroups: - - storage.k8s.io - verbs: - - patch - - resources: - - nodes - apiGroups: - - - verbs: - - get - - list - - watch - - resources: - - csinodes - apiGroups: - - storage.k8s.io - verbs: - - get - - list - - watch - - resources: - - persistentvolumeclaims/status - apiGroups: - - - verbs: - - patch - - resources: - - volumesnapshots - apiGroups: - - snapshot.storage.k8s.io - verbs: - - get - - list - - watch - - resources: - - volumesnapshotclasses - apiGroups: - - snapshot.storage.k8s.io - verbs: - - get - - list - - watch - - resources: - - volumesnapshotcontents - apiGroups: - - snapshot.storage.k8s.io - verbs: - - get - - list - - watch - - patch - - update - - resources: - - volumesnapshotcontents/status - apiGroups: - - snapshot.storage.k8s.io - verbs: - - update - - patch - - resources: - - configmaps - apiGroups: - - - verbs: - - get - - resources: - - serviceaccounts - apiGroups: - - - verbs: - - get - - resources: - - serviceaccounts/token - apiGroups: - - - verbs: - - create - - resources: - - volumegroupsnapshotclasses - apiGroups: - - groupsnapshot.storage.k8s.io - verbs: - - get - - list - - watch - - resources: - - volumegroupsnapshotcontents - apiGroups: - - groupsnapshot.storage.k8s.io - verbs: - - get - - list - - watch - - update - - patch - - resources: - - volumegroupsnapshotcontents/status - apiGroups: - - groupsnapshot.storage.k8s.io - verbs: - - update - - patch - - resources: - - volumegroupsnapshotclasses - apiGroups: - - groupsnapshot.storage.openshift.io - verbs: - - get - - list - - watch - - resources: - - volumegroupsnapshotcontents - apiGroups: - - groupsnapshot.storage.openshift.io - verbs: - - get - - list - - watch - - update - - patch - - resources: - - volumegroupsnapshotcontents/status - apiGroups: - - groupsnapshot.storage.openshift.io - verbs: - - update - - patch - - resources: - - volumegroupreplicationcontents - apiGroups: - - replication.storage.openshift.io - verbs: - - get - - list - - watch - - resources: - - volumegroupreplicationclasses - apiGroups: - - replication.storage.openshift.io - verbs: - - get - - list - - watch - - resources: - - tokenreviews - apiGroups: - - authentication.k8s.io - verbs: - - create - - resources: - - subjectaccessreviews - apiGroups: - - authorization.k8s.io - verbs: - - create - - resources: - - snapshotmetadataservices - apiGroups: - - cbt.storage.k8s.io - verbs: - - get - - list @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRole/nvmeof-csi-ceph-com-nodeplugin-cr ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: nvmeof-csi-ceph-com-nodeplugin-cr - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - rules: - - resources: - - secrets - apiGroups: - - - verbs: - - get - - list - - watch - - resources: - - persistentvolumes - apiGroups: - - - verbs: - - get - - list - - resources: - - volumeattachments - apiGroups: - - storage.k8s.io - verbs: - - get - - list - - resources: - - configmaps - apiGroups: - - - verbs: - - get - - resources: - - serviceaccounts - apiGroups: - - - verbs: - - get - - resources: - - serviceaccounts/token - apiGroups: - - - verbs: - - create - - resources: - - nodes - apiGroups: - - - verbs: - - get - - resources: - - tokenreviews - apiGroups: - - authentication.k8s.io - verbs: - - create - - resources: - - events - apiGroups: - - - verbs: - - list - - watch - - create - - update - - patch - - resources: - - persistentvolumeclaims - apiGroups: - - - verbs: - - get @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRole/rbd-csi-ceph-com-ctrlplugin-cr ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: rbd-csi-ceph-com-ctrlplugin-cr - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - rules: - - resources: - - secrets - apiGroups: - - - verbs: - - get - - list - - watch - - resources: - - persistentvolumes - apiGroups: - - - verbs: - - get - - list - - watch - - create - - delete - - patch - - update - - resources: - - persistentvolumeclaims - apiGroups: - - - verbs: - - get - - list - - watch - - update - - resources: - - storageclasses - apiGroups: - - storage.k8s.io - verbs: - - get - - list - - watch - - resources: - - events - apiGroups: - - - verbs: - - list - - watch - - create - - update - - patch - - resources: - - volumeattachments - apiGroups: - - storage.k8s.io - verbs: - - get - - list - - watch - - patch - - resources: - - volumeattachments/status - apiGroups: - - storage.k8s.io - verbs: - - patch - - resources: - - nodes - apiGroups: - - - verbs: - - get - - list - - watch - - resources: - - csinodes - apiGroups: - - storage.k8s.io - verbs: - - get - - list - - watch - - resources: - - persistentvolumeclaims/status - apiGroups: - - - verbs: - - patch - - resources: - - volumesnapshots - apiGroups: - - snapshot.storage.k8s.io - verbs: - - get - - list - - watch - - resources: - - volumesnapshotclasses - apiGroups: - - snapshot.storage.k8s.io - verbs: - - get - - list - - watch - - resources: - - volumesnapshotcontents - apiGroups: - - snapshot.storage.k8s.io - verbs: - - get - - list - - watch - - patch - - update - - resources: - - volumesnapshotcontents/status - apiGroups: - - snapshot.storage.k8s.io - verbs: - - update - - patch - - resources: - - configmaps - apiGroups: - - - verbs: - - get - - resources: - - serviceaccounts - apiGroups: - - - verbs: - - get - - resources: - - serviceaccounts/token - apiGroups: - - - verbs: - - create - - resources: - - volumegroupsnapshotclasses - apiGroups: - - groupsnapshot.storage.k8s.io - verbs: - - get - - list - - watch - - resources: - - volumegroupsnapshotcontents - apiGroups: - - groupsnapshot.storage.k8s.io - verbs: - - get - - list - - watch - - update - - patch - - resources: - - volumegroupsnapshotcontents/status - apiGroups: - - groupsnapshot.storage.k8s.io - verbs: - - update - - patch - - resources: - - volumegroupsnapshotclasses - apiGroups: - - groupsnapshot.storage.openshift.io - verbs: - - get - - list - - watch - - resources: - - volumegroupsnapshotcontents - apiGroups: - - groupsnapshot.storage.openshift.io - verbs: - - get - - list - - watch - - update - - patch - - resources: - - volumegroupsnapshotcontents/status - apiGroups: - - groupsnapshot.storage.openshift.io - verbs: - - update - - patch - - resources: - - volumegroupreplicationcontents - apiGroups: - - replication.storage.openshift.io - verbs: - - get - - list - - watch - - resources: - - volumegroupreplicationclasses - apiGroups: - - replication.storage.openshift.io - verbs: - - get - - list - - watch - - resources: - - tokenreviews - apiGroups: - - authentication.k8s.io - verbs: - - create - - resources: - - subjectaccessreviews - apiGroups: - - authorization.k8s.io - verbs: - - create - - resources: - - snapshotmetadataservices - apiGroups: - - cbt.storage.k8s.io - verbs: - - get - - list @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRole/rbd-csi-ceph-com-nodeplugin-cr ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRole - metadata: - name: rbd-csi-ceph-com-nodeplugin-cr - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - rules: - - resources: - - secrets - apiGroups: - - - verbs: - - get - - list - - watch - - resources: - - persistentvolumes - apiGroups: - - - verbs: - - get - - list - - resources: - - volumeattachments - apiGroups: - - storage.k8s.io - verbs: - - get - - list - - resources: - - configmaps - apiGroups: - - - verbs: - - get - - resources: - - serviceaccounts - apiGroups: - - - verbs: - - get - - resources: - - serviceaccounts/token - apiGroups: - - - verbs: - - create - - resources: - - nodes - apiGroups: - - - verbs: - - get - - resources: - - tokenreviews - apiGroups: - - authentication.k8s.io - verbs: - - create - - resources: - - events - apiGroups: - - - verbs: - - list - - watch - - create - - update - - patch - - resources: - - persistentvolumeclaims - apiGroups: - - - verbs: - - get @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRoleBinding/cephfs-csi-ceph-com-ctrlplugin-crb ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: cephfs-csi-ceph-com-ctrlplugin-crb - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - roleRef: - name: cephfs-csi-ceph-com-ctrlplugin-cr - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - subjects: - - name: cephfs-csi-ceph-com-ctrlplugin-sa - kind: ServiceAccount - namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRoleBinding/cephfs-csi-ceph-com-nodeplugin-crb ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: cephfs-csi-ceph-com-nodeplugin-crb - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - roleRef: - name: cephfs-csi-ceph-com-nodeplugin-cr - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - subjects: - - name: cephfs-csi-ceph-com-nodeplugin-sa - kind: ServiceAccount - namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRoleBinding/nfs-csi-ceph-com-ctrlplugin-crb ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: nfs-csi-ceph-com-ctrlplugin-crb - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - roleRef: - name: nfs-csi-ceph-com-ctrlplugin-cr - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - subjects: - - name: nfs-csi-ceph-com-ctrlplugin-sa - kind: ServiceAccount - namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRoleBinding/nfs-csi-ceph-com-nodeplugin-crb ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: nfs-csi-ceph-com-nodeplugin-crb - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - roleRef: - name: nfs-csi-ceph-com-nodeplugin-cr - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - subjects: - - name: nfs-csi-ceph-com-nodeplugin-sa - kind: ServiceAccount - namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRoleBinding/nvmeof-csi-ceph-com-ctrlplugin-crb ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: nvmeof-csi-ceph-com-ctrlplugin-crb - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - roleRef: - name: nvmeof-csi-ceph-com-ctrlplugin-cr - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - subjects: - - name: nvmeof-csi-ceph-com-ctrlplugin-sa - kind: ServiceAccount - namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRoleBinding/nvmeof-csi-ceph-com-nodeplugin-crb ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: nvmeof-csi-ceph-com-nodeplugin-crb - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - roleRef: - name: nvmeof-csi-ceph-com-nodeplugin-cr - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - subjects: - - name: nvmeof-csi-ceph-com-nodeplugin-sa - kind: ServiceAccount - namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRoleBinding/rbd-csi-ceph-com-ctrlplugin-crb ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: rbd-csi-ceph-com-ctrlplugin-crb - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - roleRef: - name: rbd-csi-ceph-com-ctrlplugin-cr - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - subjects: - - name: rbd-csi-ceph-com-ctrlplugin-sa - kind: ServiceAccount - namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRoleBinding/rbd-csi-ceph-com-nodeplugin-crb ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: ClusterRoleBinding - metadata: - name: rbd-csi-ceph-com-nodeplugin-crb - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - roleRef: - name: rbd-csi-ceph-com-nodeplugin-cr - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - subjects: - - name: rbd-csi-ceph-com-nodeplugin-sa - kind: ServiceAccount - namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/Role/cephfs-csi-ceph-com-ctrlplugin-r ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: Role - metadata: - name: cephfs-csi-ceph-com-ctrlplugin-r - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - rules: - - resources: - - leases - apiGroups: - - coordination.k8s.io - verbs: - - get - - watch - - list - - delete - - update - - create - - resources: - - csiaddonsnodes - apiGroups: - - csiaddons.openshift.io - verbs: - - get - - watch - - list - - create - - update - - delete - - resources: - - pods - apiGroups: - - - verbs: - - get - - resources: - - replicasets - apiGroups: - - apps - verbs: - - get - - resources: - - deployments/finalizers - - daemonsets/finalizers - apiGroups: - - apps - verbs: - - update @@ (root level) @@ # rbac.authorization.k8s.io/v1/Role/cephfs-csi-ceph-com-nodeplugin-r ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: Role - metadata: - name: cephfs-csi-ceph-com-nodeplugin-r - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - rules: - - resources: - - csiaddonsnodes - apiGroups: - - csiaddons.openshift.io - verbs: - - get - - watch - - list - - create - - update - - delete - - resources: - - pods - apiGroups: - - - verbs: - - get - - resources: - - replicasets - apiGroups: - - apps - verbs: - - get - - resources: - - deployments/finalizers - - daemonsets/finalizers - apiGroups: - - apps - verbs: - - update @@ (root level) @@ # rbac.authorization.k8s.io/v1/Role/nvmeof-csi-ceph-com-ctrlplugin-r ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: Role - metadata: - name: nvmeof-csi-ceph-com-ctrlplugin-r - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - rules: - - resources: - - leases - apiGroups: - - coordination.k8s.io - verbs: - - get - - watch - - list - - delete - - update - - create - - resources: - - csiaddonsnodes - apiGroups: - - csiaddons.openshift.io - verbs: - - get - - watch - - list - - create - - update - - delete - - resources: - - pods - apiGroups: - - - verbs: - - get - - resources: - - replicasets - apiGroups: - - apps - verbs: - - get - - resources: - - deployments/finalizers - - daemonsets/finalizers - apiGroups: - - apps - verbs: - - update @@ (root level) @@ # rbac.authorization.k8s.io/v1/Role/nvmeof-csi-ceph-com-nodeplugin-r ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: Role - metadata: - name: nvmeof-csi-ceph-com-nodeplugin-r - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - rules: - - resources: - - csiaddonsnodes - apiGroups: - - csiaddons.openshift.io - verbs: - - get - - watch - - list - - create - - update - - delete - - resources: - - pods - apiGroups: - - - verbs: - - get - - resources: - - replicasets - apiGroups: - - apps - verbs: - - get - - resources: - - deployments/finalizers - - daemonsets/finalizers - apiGroups: - - apps - verbs: - - update @@ (root level) @@ # rbac.authorization.k8s.io/v1/Role/rbd-csi-ceph-com-ctrlplugin-r ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: Role - metadata: - name: rbd-csi-ceph-com-ctrlplugin-r - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - rules: - - resources: - - leases - apiGroups: - - coordination.k8s.io - verbs: - - get - - watch - - list - - delete - - update - - create - - resources: - - csiaddonsnodes - apiGroups: - - csiaddons.openshift.io - verbs: - - get - - watch - - list - - create - - update - - delete - - resources: - - pods - apiGroups: - - - verbs: - - get - - resources: - - replicasets - apiGroups: - - apps - verbs: - - get - - resources: - - deployments/finalizers - - daemonsets/finalizers - apiGroups: - - apps - verbs: - - update @@ (root level) @@ # rbac.authorization.k8s.io/v1/Role/rbd-csi-ceph-com-nodeplugin-r ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: Role - metadata: - name: rbd-csi-ceph-com-nodeplugin-r - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - rules: - - resources: - - csiaddonsnodes - apiGroups: - - csiaddons.openshift.io - verbs: - - get - - watch - - list - - create - - update - - delete - - resources: - - pods - apiGroups: - - - verbs: - - get - - resources: - - replicasets - apiGroups: - - apps - verbs: - - get - - resources: - - deployments/finalizers - - daemonsets/finalizers - apiGroups: - - apps - verbs: - - update @@ (root level) @@ # rbac.authorization.k8s.io/v1/RoleBinding/cephfs-csi-ceph-com-ctrlplugin-rb ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: cephfs-csi-ceph-com-ctrlplugin-rb - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - roleRef: - name: cephfs-csi-ceph-com-ctrlplugin-r - apiGroup: rbac.authorization.k8s.io - kind: Role - subjects: - - name: cephfs-csi-ceph-com-ctrlplugin-sa - kind: ServiceAccount - namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/RoleBinding/cephfs-csi-ceph-com-nodeplugin-rb ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: cephfs-csi-ceph-com-nodeplugin-rb - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - roleRef: - name: cephfs-csi-ceph-com-nodeplugin-r - apiGroup: rbac.authorization.k8s.io - kind: Role - subjects: - - name: cephfs-csi-ceph-com-nodeplugin-sa - kind: ServiceAccount - namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/RoleBinding/nvmeof-csi-ceph-com-ctrlplugin-rb ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: nvmeof-csi-ceph-com-ctrlplugin-rb - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - roleRef: - name: nvmeof-csi-ceph-com-ctrlplugin-r - apiGroup: rbac.authorization.k8s.io - kind: Role - subjects: - - name: nvmeof-csi-ceph-com-ctrlplugin-sa - kind: ServiceAccount - namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/RoleBinding/nvmeof-csi-ceph-com-nodeplugin-rb ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: nvmeof-csi-ceph-com-nodeplugin-rb - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - roleRef: - name: nvmeof-csi-ceph-com-nodeplugin-r - apiGroup: rbac.authorization.k8s.io - kind: Role - subjects: - - name: nvmeof-csi-ceph-com-nodeplugin-sa - kind: ServiceAccount - namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/RoleBinding/rbd-csi-ceph-com-ctrlplugin-rb ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: rbd-csi-ceph-com-ctrlplugin-rb - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - roleRef: - name: rbd-csi-ceph-com-ctrlplugin-r - apiGroup: rbac.authorization.k8s.io - kind: Role - subjects: - - name: rbd-csi-ceph-com-ctrlplugin-sa - kind: ServiceAccount - namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/RoleBinding/rbd-csi-ceph-com-nodeplugin-rb ! - one document removed: - apiVersion: rbac.authorization.k8s.io/v1 - kind: RoleBinding - metadata: - name: rbd-csi-ceph-com-nodeplugin-rb - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - roleRef: - name: rbd-csi-ceph-com-nodeplugin-r - apiGroup: rbac.authorization.k8s.io - kind: Role - subjects: - - name: rbd-csi-ceph-com-nodeplugin-sa - kind: ServiceAccount - namespace: rook-ceph @@ (root level) @@ # csi.ceph.io/v1/Driver/rook-ceph/cephfs.csi.ceph.com ! - one document removed: - apiVersion: csi.ceph.io/v1 - kind: Driver - metadata: - name: cephfs.csi.ceph.com - namespace: rook-ceph - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - spec: - attachRequired: true - cephFsClientType: kernel - controllerPlugin: - hostNetwork: false - privileged: false - replicas: 1 - serviceAccountName: cephfs-csi-ceph-com-ctrlplugin-sa - tolerations: [] - volumes: [] - deployCsiAddons: false - enableFencing: false - fsGroupPolicy: None - fuseMountOptions: {} - generateOMapInfo: false - grpcTimeout: 30 - kernelMountOptions: {} - log: - rotation: - maxFiles: 7 - maxLogSize: 10Gi - periodicity: daily - verbosity: 0 - nodePlugin: - imagePullPolicy: IfNotPresent - serviceAccountName: cephfs-csi-ceph-com-nodeplugin-sa - tolerations: [] - volumes: [] - snapshotPolicy: volumeSnapshot @@ (root level) @@ # csi.ceph.io/v1/Driver/rook-ceph/nfs.csi.ceph.com ! - one document removed: - apiVersion: csi.ceph.io/v1 - kind: Driver - metadata: - name: nfs.csi.ceph.com - namespace: rook-ceph - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - spec: - attachRequired: true - cephFsClientType: kernel - controllerPlugin: - hostNetwork: false - privileged: false - replicas: 1 - serviceAccountName: nfs-csi-ceph-com-ctrlplugin-sa - tolerations: [] - volumes: [] - deployCsiAddons: false - enableFencing: false - fsGroupPolicy: None - fuseMountOptions: {} - generateOMapInfo: false - grpcTimeout: 30 - kernelMountOptions: {} - log: - rotation: - maxFiles: 7 - maxLogSize: 10Gi - periodicity: daily - verbosity: 0 - nodePlugin: - imagePullPolicy: IfNotPresent - serviceAccountName: nfs-csi-ceph-com-nodeplugin-sa - tolerations: [] - volumes: [] - snapshotPolicy: volumeSnapshot @@ (root level) @@ # csi.ceph.io/v1/Driver/rook-ceph/nvmeof.csi.ceph.com ! - one document removed: - apiVersion: csi.ceph.io/v1 - kind: Driver - metadata: - name: nvmeof.csi.ceph.com - namespace: rook-ceph - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - spec: - attachRequired: true - cephFsClientType: kernel - controllerPlugin: - hostNetwork: false - privileged: false - replicas: 1 - serviceAccountName: nvmeof-csi-ceph-com-ctrlplugin-sa - tolerations: [] - volumes: [] - deployCsiAddons: false - enableFencing: false - fsGroupPolicy: File - fuseMountOptions: {} - generateOMapInfo: false - grpcTimeout: 30 - kernelMountOptions: {} - log: - rotation: - maxFiles: 7 - maxLogSize: 10Gi - periodicity: daily - verbosity: 0 - nodePlugin: - imagePullPolicy: IfNotPresent - serviceAccountName: nvmeof-csi-ceph-com-nodeplugin-sa - tolerations: [] - volumes: [] - snapshotPolicy: none @@ (root level) @@ # csi.ceph.io/v1/Driver/rook-ceph/rbd.csi.ceph.com ! - one document removed: - apiVersion: csi.ceph.io/v1 - kind: Driver - metadata: - name: rbd.csi.ceph.com - namespace: rook-ceph - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - spec: - attachRequired: true - cephFsClientType: kernel - controllerPlugin: - hostNetwork: false - privileged: false - replicas: 1 - serviceAccountName: rbd-csi-ceph-com-ctrlplugin-sa - tolerations: [] - volumes: [] - deployCsiAddons: false - enableFencing: false - fsGroupPolicy: File - fuseMountOptions: {} - generateOMapInfo: false - grpcTimeout: 30 - kernelMountOptions: {} - log: - rotation: - maxFiles: 7 - maxLogSize: 10Gi - periodicity: daily - verbosity: 0 - nodePlugin: - imagePullPolicy: IfNotPresent - serviceAccountName: rbd-csi-ceph-com-nodeplugin-sa - tolerations: [] - volumes: [] - snapshotPolicy: none @@ (root level) @@ # csi.ceph.io/v1/OperatorConfig/null/ceph-csi-operator-config ! - one document removed: - apiVersion: csi.ceph.io/v1 - kind: OperatorConfig - metadata: - name: ceph-csi-operator-config - namespace: null - labels: - helm.toolkit.fluxcd.io/name: ceph-csi-drivers - helm.toolkit.fluxcd.io/namespace: rook-ceph - spec: - driverSpecDefaults: - attachRequired: true - cephFsClientType: kernel - controllerPlugin: - affinity: - nodeAffinity: - requiredDuringSchedulingIgnoredDuringExecution: - nodeSelectorTerms: - - matchExpressions: - - key: kubernetes.io/hostname - operator: In - values: - - talos-w-01 - - talos-w-02 - - talos-gpu-01 - hostNetwork: false - imagePullPolicy: IfNotPresent - privileged: false - replicas: 1 - tolerations: [] - volumes: [] - deployCsiAddons: false - enableFencing: false - fsGroupPolicy: File - fuseMountOptions: {} - generateOMapInfo: false - grpcTimeout: 30 - kernelMountOptions: - ms_mode: prefer-crc - log: - rotation: - maxFiles: 7 - maxLogSize: 10Gi - periodicity: daily - verbosity: 0 - nodePlugin: - imagePullPolicy: IfNotPresent - kubeletDirPath: /var/lib/kubelet - tolerations: [] - volumes: [] - snapshotPolicy: none @@ (root level) @@ # v1/ServiceAccount/ceph-csi ! - one document removed: - apiVersion: v1 - kind: ServiceAccount - metadata: - name: ceph-csi - labels: - app.kubernetes.io/instance: rook-ceph - app.kubernetes.io/managed-by: Helm - app.kubernetes.io/name: ceph-csi - helm.toolkit.fluxcd.io/name: rook-ceph - helm.toolkit.fluxcd.io/namespace: rook-ceph - automountServiceAccountToken: true @@ (root level) @@ # v1/ConfigMap/rook-ceph/rook-csi-operator-image-set-configmap ! - one document removed: - apiVersion: v1 - kind: ConfigMap - metadata: - name: rook-csi-operator-image-set-configmap - namespace: rook-ceph - labels: - app.kubernetes.io/created-by: helm - app.kubernetes.io/instance: rook-ceph - app.kubernetes.io/managed-by: Helm - app.kubernetes.io/name: rook-ceph - app.kubernetes.io/part-of: rook-ceph-operator - helm.toolkit.fluxcd.io/name: rook-ceph - helm.toolkit.fluxcd.io/namespace: rook-ceph - operator: rook - storage-backend: ceph - data: - addons: "quay.io/csiaddons/k8s-sidecar:v0.14.0" - attacher: "registry.k8s.io/sig-storage/csi-attacher:v4.12.0" - plugin: "quay.io/cephcsi/cephcsi:v3.17.0" - provisioner: "registry.k8s.io/sig-storage/csi-provisioner:v6.2.0" - registrar: "registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.17.0" - resizer: "registry.k8s.io/sig-storage/csi-resizer:v2.1.0" - snapshotter: "registry.k8s.io/sig-storage/csi-snapshotter:v8.5.0" @@ (root level) @@ # v1/ServiceAccount/rook-ceph/ceph-csi-cephfs-ctrlplugin-sa ! + one document added: + apiVersion: v1 + kind: ServiceAccount + metadata: + name: ceph-csi-cephfs-ctrlplugin-sa + namespace: rook-ceph + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph @@ (root level) @@ # v1/ServiceAccount/rook-ceph/ceph-csi-cephfs-nodeplugin-sa ! + one document added: + apiVersion: v1 + kind: ServiceAccount + metadata: + name: ceph-csi-cephfs-nodeplugin-sa + namespace: rook-ceph + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph @@ (root level) @@ # v1/ServiceAccount/rook-ceph/ceph-csi-controller-manager ! + one document added: + apiVersion: v1 + kind: ServiceAccount + metadata: + name: ceph-csi-controller-manager + namespace: rook-ceph + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph @@ (root level) @@ # v1/ServiceAccount/rook-ceph/ceph-csi-nfs-ctrlplugin-sa ! + one document added: + apiVersion: v1 + kind: ServiceAccount + metadata: + name: ceph-csi-nfs-ctrlplugin-sa + namespace: rook-ceph + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph @@ (root level) @@ # v1/ServiceAccount/rook-ceph/ceph-csi-nfs-nodeplugin-sa ! + one document added: + apiVersion: v1 + kind: ServiceAccount + metadata: + name: ceph-csi-nfs-nodeplugin-sa + namespace: rook-ceph + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph @@ (root level) @@ # v1/ServiceAccount/rook-ceph/ceph-csi-nvmeof-ctrlplugin-sa ! + one document added: + apiVersion: v1 + kind: ServiceAccount + metadata: + name: ceph-csi-nvmeof-ctrlplugin-sa + namespace: rook-ceph + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph @@ (root level) @@ # v1/ServiceAccount/rook-ceph/ceph-csi-nvmeof-nodeplugin-sa ! + one document added: + apiVersion: v1 + kind: ServiceAccount + metadata: + name: ceph-csi-nvmeof-nodeplugin-sa + namespace: rook-ceph + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph @@ (root level) @@ # v1/ServiceAccount/rook-ceph/ceph-csi-rbd-ctrlplugin-sa ! + one document added: + apiVersion: v1 + kind: ServiceAccount + metadata: + name: ceph-csi-rbd-ctrlplugin-sa + namespace: rook-ceph + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph @@ (root level) @@ # v1/ServiceAccount/rook-ceph/ceph-csi-rbd-nodeplugin-sa ! + one document added: + apiVersion: v1 + kind: ServiceAccount + metadata: + name: ceph-csi-rbd-nodeplugin-sa + namespace: rook-ceph + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph @@ (root level) @@ # v1/ServiceAccount/rook-ceph/rook-csi-cephfs-plugin-sa ! + one document added: + apiVersion: v1 + kind: ServiceAccount + metadata: + name: rook-csi-cephfs-plugin-sa + namespace: rook-ceph + labels: + app.kubernetes.io/created-by: helm + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: rook-ceph + app.kubernetes.io/part-of: rook-ceph-operator + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + operator: rook + storage-backend: ceph @@ (root level) @@ # v1/ServiceAccount/rook-ceph/rook-csi-cephfs-provisioner-sa ! + one document added: + apiVersion: v1 + kind: ServiceAccount + metadata: + name: rook-csi-cephfs-provisioner-sa + namespace: rook-ceph + labels: + app.kubernetes.io/created-by: helm + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: rook-ceph + app.kubernetes.io/part-of: rook-ceph-operator + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + operator: rook + storage-backend: ceph @@ (root level) @@ # v1/ServiceAccount/rook-ceph/rook-csi-rbd-plugin-sa ! + one document added: + apiVersion: v1 + kind: ServiceAccount + metadata: + name: rook-csi-rbd-plugin-sa + namespace: rook-ceph + labels: + app.kubernetes.io/created-by: helm + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: rook-ceph + app.kubernetes.io/part-of: rook-ceph-operator + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + operator: rook + storage-backend: ceph @@ (root level) @@ # v1/ServiceAccount/rook-ceph/rook-csi-rbd-provisioner-sa ! + one document added: + apiVersion: v1 + kind: ServiceAccount + metadata: + name: rook-csi-rbd-provisioner-sa + namespace: rook-ceph + labels: + app.kubernetes.io/created-by: helm + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: rook-ceph + app.kubernetes.io/part-of: rook-ceph-operator + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + operator: rook + storage-backend: ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRole/ceph-csi-cephfs-ctrlplugin-cr ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRole + metadata: + name: ceph-csi-cephfs-ctrlplugin-cr + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + rules: + - resources: + - secrets + apiGroups: + - + verbs: + - get + - list + - watch + - resources: + - configmaps + apiGroups: + - + verbs: + - get + - resources: + - nodes + apiGroups: + - + verbs: + - get + - list + - watch + - resources: + - csinodes + apiGroups: + - storage.k8s.io + verbs: + - get + - list + - watch + - resources: + - persistentvolumes + apiGroups: + - + verbs: + - get + - list + - watch + - create + - delete + - patch + - update + - resources: + - persistentvolumeclaims + apiGroups: + - + verbs: + - get + - list + - watch + - patch + - update + - resources: + - storageclasses + apiGroups: + - storage.k8s.io + verbs: + - get + - list + - watch + - resources: + - events + apiGroups: + - + verbs: + - list + - watch + - create + - update + - patch + - resources: + - volumeattachments + apiGroups: + - storage.k8s.io + verbs: + - get + - list + - watch + - patch + - resources: + - volumeattachments/status + apiGroups: + - storage.k8s.io + verbs: + - patch + - resources: + - persistentvolumeclaims/status + apiGroups: + - + verbs: + - patch + - resources: + - volumesnapshots + apiGroups: + - snapshot.storage.k8s.io + verbs: + - get + - list + - resources: + - volumesnapshotclasses + apiGroups: + - snapshot.storage.k8s.io + verbs: + - get + - list + - watch + - resources: + - volumesnapshotcontents + apiGroups: + - snapshot.storage.k8s.io + verbs: + - get + - list + - watch + - patch + - update + - resources: + - volumesnapshotcontents/status + apiGroups: + - snapshot.storage.k8s.io + verbs: + - update + - patch + - resources: + - volumegroupsnapshotclasses + apiGroups: + - groupsnapshot.storage.k8s.io + verbs: + - get + - list + - watch + - resources: + - volumegroupsnapshotcontents + apiGroups: + - groupsnapshot.storage.k8s.io + verbs: + - get + - list + - watch + - update + - patch + - resources: + - volumegroupsnapshotcontents/status + apiGroups: + - groupsnapshot.storage.k8s.io + verbs: + - update + - patch + - resources: + - volumegroupsnapshotclasses + apiGroups: + - groupsnapshot.storage.openshift.io + verbs: + - get + - list + - watch + - resources: + - volumegroupsnapshotcontents + apiGroups: + - groupsnapshot.storage.openshift.io + verbs: + - get + - list + - watch + - update + - patch + - resources: + - volumegroupsnapshotcontents/status + apiGroups: + - groupsnapshot.storage.openshift.io + verbs: + - update + - patch + - resources: + - serviceaccounts + apiGroups: + - + verbs: + - get + - resources: + - serviceaccounts/token + apiGroups: + - + verbs: + - create + - resources: + - tokenreviews + apiGroups: + - authentication.k8s.io + verbs: + - create + - resources: + - volumeattributesclasses + apiGroups: + - storage.k8s.io + verbs: + - get + - list + - watch @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRole/ceph-csi-cephfs-nodeplugin-cr ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRole + metadata: + name: ceph-csi-cephfs-nodeplugin-cr + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + rules: + - resources: + - nodes + apiGroups: + - + verbs: + - get + - resources: + - secrets + apiGroups: + - + verbs: + - get + - list + - watch + - resources: + - configmaps + apiGroups: + - + verbs: + - get + - resources: + - serviceaccounts + apiGroups: + - + verbs: + - get + - resources: + - serviceaccounts/token + apiGroups: + - + verbs: + - create + - resources: + - events + apiGroups: + - + verbs: + - list + - watch + - create + - update + - patch + - resources: + - persistentvolumes + - persistentvolumeclaims + apiGroups: + - + verbs: + - get + - resources: + - tokenreviews + apiGroups: + - authentication.k8s.io + verbs: + - create @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRole/ceph-csi-nfs-ctrlplugin-cr ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRole + metadata: + name: ceph-csi-nfs-ctrlplugin-cr + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + rules: + - resources: + - persistentvolumes + apiGroups: + - + verbs: + - get + - list + - watch + - create + - update + - delete + - patch + - resources: + - persistentvolumeclaims + apiGroups: + - + verbs: + - get + - list + - watch + - patch + - update + - resources: + - storageclasses + apiGroups: + - storage.k8s.io + verbs: + - get + - list + - watch + - resources: + - events + apiGroups: + - + verbs: + - get + - list + - watch + - create + - update + - patch + - resources: + - csinodes + apiGroups: + - storage.k8s.io + verbs: + - get + - list + - watch + - resources: + - nodes + apiGroups: + - + verbs: + - get + - list + - watch + - resources: + - leases + apiGroups: + - coordination.k8s.io + verbs: + - get + - list + - watch + - create + - update + - patch + - resources: + - secrets + apiGroups: + - + verbs: + - get + - resources: + - volumesnapshotclasses + apiGroups: + - snapshot.storage.k8s.io + verbs: + - get + - list + - watch + - resources: + - volumesnapshotcontents + apiGroups: + - snapshot.storage.k8s.io + verbs: + - get + - list + - watch + - update + - patch + - resources: + - volumesnapshotcontents/status + apiGroups: + - snapshot.storage.k8s.io + verbs: + - update + - patch + - resources: + - volumesnapshots + apiGroups: + - snapshot.storage.k8s.io + verbs: + - get + - list + - resources: + - persistentvolumeclaims/status + apiGroups: + - + verbs: + - patch + - resources: + - volumeattachments + apiGroups: + - storage.k8s.io + verbs: + - get + - list + - watch + - patch + - resources: + - volumeattachments/status + apiGroups: + - storage.k8s.io + verbs: + - patch + - resources: + - volumeattributesclasses + apiGroups: + - storage.k8s.io + verbs: + - get + - list + - watch @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRole/ceph-csi-nfs-nodeplugin-cr ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRole + metadata: + name: ceph-csi-nfs-nodeplugin-cr + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + rules: + - resources: + - nodes + apiGroups: + - + verbs: + - get @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRole/ceph-csi-nvmeof-ctrlplugin-cr ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRole + metadata: + name: ceph-csi-nvmeof-ctrlplugin-cr + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + rules: + - resources: + - secrets + apiGroups: + - + verbs: + - get + - list + - watch + - resources: + - persistentvolumes + apiGroups: + - + verbs: + - get + - list + - watch + - create + - delete + - patch + - update + - resources: + - persistentvolumeclaims + apiGroups: + - + verbs: + - get + - list + - watch + - update + - resources: + - storageclasses + apiGroups: + - storage.k8s.io + verbs: + - get + - list + - watch + - resources: + - events + apiGroups: + - + verbs: + - list + - watch + - create + - update + - patch + - resources: + - volumeattachments + apiGroups: + - storage.k8s.io + verbs: + - get + - list + - watch + - patch + - resources: + - volumeattachments/status + apiGroups: + - storage.k8s.io + verbs: + - patch + - resources: + - nodes + apiGroups: + - + verbs: + - get + - list + - watch + - resources: + - csinodes + apiGroups: + - storage.k8s.io + verbs: + - get + - list + - watch + - resources: + - persistentvolumeclaims/status + apiGroups: + - + verbs: + - patch + - resources: + - configmaps + apiGroups: + - + verbs: + - get + - resources: + - serviceaccounts + apiGroups: + - + verbs: + - get + - resources: + - serviceaccounts/token + apiGroups: + - + verbs: + - create + - resources: + - tokenreviews + apiGroups: + - authentication.k8s.io + verbs: + - create + - resources: + - subjectaccessreviews + apiGroups: + - authorization.k8s.io + verbs: + - create @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRole/ceph-csi-nvmeof-nodeplugin-cr ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRole + metadata: + name: ceph-csi-nvmeof-nodeplugin-cr + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + rules: + - resources: + - secrets + apiGroups: + - + verbs: + - get + - list + - resources: + - persistentvolumes + apiGroups: + - + verbs: + - get + - list + - resources: + - volumeattachments + apiGroups: + - storage.k8s.io + verbs: + - get + - list + - resources: + - configmaps + apiGroups: + - + verbs: + - get + - resources: + - serviceaccounts + apiGroups: + - + verbs: + - get + - resources: + - serviceaccounts/token + apiGroups: + - + verbs: + - create + - resources: + - nodes + apiGroups: + - + verbs: + - get + - resources: + - tokenreviews + apiGroups: + - authentication.k8s.io + verbs: + - create + - resources: + - events + apiGroups: + - + verbs: + - list + - watch + - create + - update + - patch + - resources: + - persistentvolumeclaims + apiGroups: + - + verbs: + - get @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRole/ceph-csi-rbd-ctrlplugin-cr ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRole + metadata: + name: ceph-csi-rbd-ctrlplugin-cr + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + rules: + - resources: + - secrets + apiGroups: + - + verbs: + - get + - list + - watch + - resources: + - persistentvolumes + apiGroups: + - + verbs: + - get + - list + - watch + - create + - delete + - patch + - update + - resources: + - persistentvolumeclaims + apiGroups: + - + verbs: + - get + - list + - watch + - update + - resources: + - storageclasses + apiGroups: + - storage.k8s.io + verbs: + - get + - list + - watch + - resources: + - events + apiGroups: + - + verbs: + - list + - watch + - create + - update + - patch + - resources: + - volumeattachments + apiGroups: + - storage.k8s.io + verbs: + - get + - list + - watch + - patch + - resources: + - volumeattachments/status + apiGroups: + - storage.k8s.io + verbs: + - patch + - resources: + - nodes + apiGroups: + - + verbs: + - get + - list + - watch + - resources: + - csinodes + apiGroups: + - storage.k8s.io + verbs: + - get + - list + - watch + - resources: + - persistentvolumeclaims/status + apiGroups: + - + verbs: + - patch + - resources: + - volumesnapshots + apiGroups: + - snapshot.storage.k8s.io + verbs: + - get + - list + - watch + - resources: + - volumesnapshotclasses + apiGroups: + - snapshot.storage.k8s.io + verbs: + - get + - list + - watch + - resources: + - volumesnapshotcontents + apiGroups: + - snapshot.storage.k8s.io + verbs: + - get + - list + - watch + - patch + - update + - resources: + - volumesnapshotcontents/status + apiGroups: + - snapshot.storage.k8s.io + verbs: + - update + - patch + - resources: + - configmaps + apiGroups: + - + verbs: + - get + - resources: + - serviceaccounts + apiGroups: + - + verbs: + - get + - resources: + - serviceaccounts/token + apiGroups: + - + verbs: + - create + - resources: + - volumegroupsnapshotclasses + apiGroups: + - groupsnapshot.storage.k8s.io + verbs: + - get + - list + - watch + - resources: + - volumegroupsnapshotcontents + apiGroups: + - groupsnapshot.storage.k8s.io + verbs: + - get + - list + - watch + - update + - patch + - resources: + - volumegroupsnapshotcontents/status + apiGroups: + - groupsnapshot.storage.k8s.io + verbs: + - update + - patch + - resources: + - volumegroupsnapshotclasses + apiGroups: + - groupsnapshot.storage.openshift.io + verbs: + - get + - list + - watch + - resources: + - volumegroupsnapshotcontents + apiGroups: + - groupsnapshot.storage.openshift.io + verbs: + - get + - list + - watch + - update + - patch + - resources: + - volumegroupsnapshotcontents/status + apiGroups: + - groupsnapshot.storage.openshift.io + verbs: + - update + - patch + - resources: + - volumegroupreplicationcontents + apiGroups: + - replication.storage.openshift.io + verbs: + - get + - list + - watch + - resources: + - volumegroupreplicationclasses + apiGroups: + - replication.storage.openshift.io + verbs: + - get + - list + - watch + - resources: + - tokenreviews + apiGroups: + - authentication.k8s.io + verbs: + - create + - resources: + - subjectaccessreviews + apiGroups: + - authorization.k8s.io + verbs: + - create + - resources: + - snapshotmetadataservices + apiGroups: + - cbt.storage.k8s.io + verbs: + - get + - list + - resources: + - volumeattributesclasses + apiGroups: + - storage.k8s.io + verbs: + - get + - list + - watch @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRole/ceph-csi-rbd-nodeplugin-cr ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRole + metadata: + name: ceph-csi-rbd-nodeplugin-cr + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + rules: + - resources: + - secrets + apiGroups: + - + verbs: + - get + - list + - watch + - resources: + - persistentvolumes + apiGroups: + - + verbs: + - get + - list + - resources: + - volumeattachments + apiGroups: + - storage.k8s.io + verbs: + - get + - list + - resources: + - configmaps + apiGroups: + - + verbs: + - get + - resources: + - serviceaccounts + apiGroups: + - + verbs: + - get + - resources: + - serviceaccounts/token + apiGroups: + - + verbs: + - create + - resources: + - nodes + apiGroups: + - + verbs: + - get + - resources: + - tokenreviews + apiGroups: + - authentication.k8s.io + verbs: + - create + - resources: + - events + apiGroups: + - + verbs: + - list + - watch + - create + - update + - patch + - resources: + - persistentvolumeclaims + apiGroups: + - + verbs: + - get @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRole/cephfs-csi-nodeplugin ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRole + metadata: + name: cephfs-csi-nodeplugin + labels: + app.kubernetes.io/created-by: helm + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: rook-ceph + app.kubernetes.io/part-of: rook-ceph-operator + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + operator: rook + storage-backend: ceph + rules: + - resources: + - nodes + apiGroups: + - + verbs: + - get + - resources: + - secrets + apiGroups: + - + verbs: + - get + - resources: + - configmaps + apiGroups: + - + verbs: + - get + - resources: + - serviceaccounts + apiGroups: + - + verbs: + - get + - resources: + - serviceaccounts/token + apiGroups: + - + verbs: + - create @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRole/cephfs-external-provisioner-runner ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRole + metadata: + name: cephfs-external-provisioner-runner + labels: + app.kubernetes.io/created-by: helm + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: rook-ceph + app.kubernetes.io/part-of: rook-ceph-operator + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + operator: rook + storage-backend: ceph + rules: + - resources: + - secrets + apiGroups: + - + verbs: + - get + - list + - resources: + - configmaps + apiGroups: + - + verbs: + - get + - resources: + - nodes + apiGroups: + - + verbs: + - get + - list + - watch + - resources: + - csinodes + apiGroups: + - storage.k8s.io + verbs: + - get + - list + - watch + - resources: + - persistentvolumes + apiGroups: + - + verbs: + - get + - list + - watch + - create + - update + - delete + - patch + - resources: + - persistentvolumeclaims + apiGroups: + - + verbs: + - get + - list + - watch + - patch + - update + - resources: + - storageclasses + apiGroups: + - storage.k8s.io + verbs: + - get + - list + - watch + - resources: + - events + apiGroups: + - + verbs: + - list + - watch + - create + - update + - patch + - resources: + - events + apiGroups: + - events.k8s.io + verbs: + - create + - patch + - update + - resources: + - volumeattachments + apiGroups: + - storage.k8s.io + verbs: + - get + - list + - watch + - patch + - resources: + - volumeattachments/status + apiGroups: + - storage.k8s.io + verbs: + - patch + - resources: + - persistentvolumeclaims/status + apiGroups: + - + verbs: + - patch + - resources: + - volumesnapshots + apiGroups: + - snapshot.storage.k8s.io + verbs: + - get + - list + - watch + - resources: + - volumesnapshotclasses + apiGroups: + - snapshot.storage.k8s.io + verbs: + - get + - list + - watch + - resources: + - volumesnapshotcontents + apiGroups: + - snapshot.storage.k8s.io + verbs: + - get + - list + - watch + - patch + - update + - resources: + - volumesnapshotcontents/status + apiGroups: + - snapshot.storage.k8s.io + verbs: + - update + - patch + - resources: + - volumegroupsnapshotclasses + apiGroups: + - groupsnapshot.storage.k8s.io + verbs: + - get + - list + - watch + - resources: + - volumegroupsnapshotcontents + apiGroups: + - groupsnapshot.storage.k8s.io + verbs: + - get + - list + - watch + - update + - patch + - resources: + - volumegroupsnapshotcontents/status + apiGroups: + - groupsnapshot.storage.k8s.io + verbs: + - update + - patch + - resources: + - serviceaccounts + apiGroups: + - + verbs: + - get + - resources: + - serviceaccounts/token + apiGroups: + - + verbs: + - create + - resources: + - tokenreviews + apiGroups: + - authentication.k8s.io + verbs: + - create @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRole/rbd-csi-nodeplugin ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRole + metadata: + name: rbd-csi-nodeplugin + labels: + app.kubernetes.io/created-by: helm + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: rook-ceph + app.kubernetes.io/part-of: rook-ceph-operator + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + operator: rook + storage-backend: ceph + rules: + - resources: + - secrets + apiGroups: + - + verbs: + - get + - list + - resources: + - persistentvolumes + apiGroups: + - + verbs: + - get + - list + - resources: + - volumeattachments + apiGroups: + - storage.k8s.io + verbs: + - get + - list + - resources: + - configmaps + apiGroups: + - + verbs: + - get + - resources: + - serviceaccounts + apiGroups: + - + verbs: + - get + - resources: + - serviceaccounts/token + apiGroups: + - + verbs: + - create + - resources: + - nodes + apiGroups: + - + verbs: + - get + - resources: + - tokenreviews + apiGroups: + - authentication.k8s.io + verbs: + - create @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRole/rbd-external-provisioner-runner ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRole + metadata: + name: rbd-external-provisioner-runner + labels: + app.kubernetes.io/created-by: helm + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: rook-ceph + app.kubernetes.io/part-of: rook-ceph-operator + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + operator: rook + storage-backend: ceph + rules: + - resources: + - secrets + apiGroups: + - + verbs: + - get + - list + - watch + - resources: + - persistentvolumes + apiGroups: + - + verbs: + - get + - list + - watch + - create + - update + - delete + - patch + - resources: + - persistentvolumeclaims + apiGroups: + - + verbs: + - get + - list + - watch + - update + - resources: + - storageclasses + apiGroups: + - storage.k8s.io + verbs: + - get + - list + - watch + - resources: + - events + apiGroups: + - + verbs: + - list + - watch + - create + - update + - patch + - resources: + - events + apiGroups: + - events.k8s.io + verbs: + - create + - patch + - update + - resources: + - volumeattachments + apiGroups: + - storage.k8s.io + verbs: + - get + - list + - watch + - patch + - resources: + - volumeattachments/status + apiGroups: + - storage.k8s.io + verbs: + - patch + - resources: + - nodes + apiGroups: + - + verbs: + - get + - list + - watch + - resources: + - csinodes + apiGroups: + - storage.k8s.io + verbs: + - get + - list + - watch + - resources: + - persistentvolumeclaims/status + apiGroups: + - + verbs: + - patch + - resources: + - volumesnapshots + apiGroups: + - snapshot.storage.k8s.io + verbs: + - get + - list + - watch + - resources: + - volumesnapshotclasses + apiGroups: + - snapshot.storage.k8s.io + verbs: + - get + - list + - watch + - resources: + - volumesnapshotcontents + apiGroups: + - snapshot.storage.k8s.io + verbs: + - get + - list + - watch + - patch + - update + - resources: + - volumesnapshotcontents/status + apiGroups: + - snapshot.storage.k8s.io + verbs: + - update + - patch + - resources: + - volumegroupsnapshotclasses + apiGroups: + - groupsnapshot.storage.k8s.io + verbs: + - get + - list + - watch + - resources: + - volumegroupsnapshotcontents + apiGroups: + - groupsnapshot.storage.k8s.io + verbs: + - get + - list + - watch + - update + - patch + - resources: + - volumegroupsnapshotcontents/status + apiGroups: + - groupsnapshot.storage.k8s.io + verbs: + - update + - patch + - resources: + - configmaps + apiGroups: + - + verbs: + - get + - resources: + - serviceaccounts + apiGroups: + - + verbs: + - get + - resources: + - serviceaccounts/token + apiGroups: + - + verbs: + - create + - resources: + - nodes + apiGroups: + - + verbs: + - get + - list + - watch + - resources: + - referencegrants + apiGroups: + - gateway.networking.k8s.io + verbs: + - get + - list + - watch + - resources: + - volumegroupreplicationcontents + apiGroups: + - replication.storage.openshift.io + verbs: + - get + - list + - watch + - resources: + - volumegroupreplicationclasses + apiGroups: + - replication.storage.openshift.io + verbs: + - get + - list + - watch + - resources: + - tokenreviews + apiGroups: + - authentication.k8s.io + verbs: + - create @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRoleBinding/ceph-csi-cephfs-ctrlplugin-crb ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRoleBinding + metadata: + name: ceph-csi-cephfs-ctrlplugin-crb + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + roleRef: + name: ceph-csi-cephfs-ctrlplugin-cr + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + subjects: + - name: ceph-csi-cephfs-ctrlplugin-sa + kind: ServiceAccount + namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRoleBinding/ceph-csi-cephfs-nodeplugin-crb ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRoleBinding + metadata: + name: ceph-csi-cephfs-nodeplugin-crb + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + roleRef: + name: ceph-csi-cephfs-nodeplugin-cr + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + subjects: + - name: ceph-csi-cephfs-nodeplugin-sa + kind: ServiceAccount + namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRoleBinding/ceph-csi-nfs-ctrlplugin-crb ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRoleBinding + metadata: + name: ceph-csi-nfs-ctrlplugin-crb + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + roleRef: + name: ceph-csi-nfs-ctrlplugin-cr + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + subjects: + - name: ceph-csi-nfs-ctrlplugin-sa + kind: ServiceAccount + namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRoleBinding/ceph-csi-nfs-nodeplugin-crb ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRoleBinding + metadata: + name: ceph-csi-nfs-nodeplugin-crb + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + roleRef: + name: ceph-csi-nfs-nodeplugin-cr + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + subjects: + - name: ceph-csi-nfs-nodeplugin-sa + kind: ServiceAccount + namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRoleBinding/ceph-csi-nvmeof-ctrlplugin-crb ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRoleBinding + metadata: + name: ceph-csi-nvmeof-ctrlplugin-crb + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + roleRef: + name: ceph-csi-nvmeof-ctrlplugin-cr + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + subjects: + - name: ceph-csi-nvmeof-ctrlplugin-sa + kind: ServiceAccount + namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRoleBinding/ceph-csi-nvmeof-nodeplugin-crb ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRoleBinding + metadata: + name: ceph-csi-nvmeof-nodeplugin-crb + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + roleRef: + name: ceph-csi-nvmeof-nodeplugin-cr + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + subjects: + - name: ceph-csi-nvmeof-nodeplugin-sa + kind: ServiceAccount + namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRoleBinding/ceph-csi-rbd-ctrlplugin-crb ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRoleBinding + metadata: + name: ceph-csi-rbd-ctrlplugin-crb + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + roleRef: + name: ceph-csi-rbd-ctrlplugin-cr + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + subjects: + - name: ceph-csi-rbd-ctrlplugin-sa + kind: ServiceAccount + namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRoleBinding/ceph-csi-rbd-nodeplugin-crb ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRoleBinding + metadata: + name: ceph-csi-rbd-nodeplugin-crb + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + roleRef: + name: ceph-csi-rbd-nodeplugin-cr + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + subjects: + - name: ceph-csi-rbd-nodeplugin-sa + kind: ServiceAccount + namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRoleBinding/rbd-csi-nodeplugin ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRoleBinding + metadata: + name: rbd-csi-nodeplugin + labels: + app.kubernetes.io/created-by: helm + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: rook-ceph + app.kubernetes.io/part-of: rook-ceph-operator + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + operator: rook + storage-backend: ceph + roleRef: + name: rbd-csi-nodeplugin + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + subjects: + - name: rook-csi-rbd-plugin-sa + kind: ServiceAccount + namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRoleBinding/cephfs-csi-provisioner-role ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRoleBinding + metadata: + name: cephfs-csi-provisioner-role + labels: + app.kubernetes.io/created-by: helm + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: rook-ceph + app.kubernetes.io/part-of: rook-ceph-operator + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + operator: rook + storage-backend: ceph + roleRef: + name: cephfs-external-provisioner-runner + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + subjects: + - name: rook-csi-cephfs-provisioner-sa + kind: ServiceAccount + namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRoleBinding/cephfs-csi-nodeplugin-role ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRoleBinding + metadata: + name: cephfs-csi-nodeplugin-role + labels: + app.kubernetes.io/created-by: helm + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: rook-ceph + app.kubernetes.io/part-of: rook-ceph-operator + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + operator: rook + storage-backend: ceph + roleRef: + name: cephfs-csi-nodeplugin + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + subjects: + - name: rook-csi-cephfs-plugin-sa + kind: ServiceAccount + namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/ClusterRoleBinding/rbd-csi-provisioner-role ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: ClusterRoleBinding + metadata: + name: rbd-csi-provisioner-role + labels: + app.kubernetes.io/created-by: helm + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: rook-ceph + app.kubernetes.io/part-of: rook-ceph-operator + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + operator: rook + storage-backend: ceph + roleRef: + name: rbd-external-provisioner-runner + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + subjects: + - name: rook-csi-rbd-provisioner-sa + kind: ServiceAccount + namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/Role/rook-ceph/ceph-csi-cephfs-ctrlplugin-r ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: Role + metadata: + name: ceph-csi-cephfs-ctrlplugin-r + namespace: rook-ceph + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + rules: + - resources: + - leases + apiGroups: + - coordination.k8s.io + verbs: + - get + - watch + - list + - delete + - update + - create + - resources: + - csiaddonsnodes + apiGroups: + - csiaddons.openshift.io + verbs: + - get + - watch + - list + - create + - update + - delete + - resources: + - pods + apiGroups: + - + verbs: + - get + - resources: + - replicasets + apiGroups: + - apps + verbs: + - get + - resources: + - deployments/finalizers + - daemonsets/finalizers + apiGroups: + - apps + verbs: + - update @@ (root level) @@ # rbac.authorization.k8s.io/v1/Role/rook-ceph/ceph-csi-cephfs-nodeplugin-r ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: Role + metadata: + name: ceph-csi-cephfs-nodeplugin-r + namespace: rook-ceph + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + rules: + - resources: + - csiaddonsnodes + apiGroups: + - csiaddons.openshift.io + verbs: + - get + - watch + - list + - create + - update + - delete + - resources: + - pods + apiGroups: + - + verbs: + - get + - resources: + - replicasets + apiGroups: + - apps + verbs: + - get + - resources: + - deployments/finalizers + - daemonsets/finalizers + apiGroups: + - apps + verbs: + - update @@ (root level) @@ # rbac.authorization.k8s.io/v1/Role/rook-ceph/ceph-csi-nvmeof-ctrlplugin-r ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: Role + metadata: + name: ceph-csi-nvmeof-ctrlplugin-r + namespace: rook-ceph + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + rules: + - resources: + - leases + apiGroups: + - coordination.k8s.io + verbs: + - get + - watch + - list + - delete + - update + - create + - resources: + - csiaddonsnodes + apiGroups: + - csiaddons.openshift.io + verbs: + - get + - watch + - list + - create + - update + - delete + - resources: + - pods + apiGroups: + - + verbs: + - get + - resources: + - replicasets + apiGroups: + - apps + verbs: + - get + - resources: + - deployments/finalizers + - daemonsets/finalizers + apiGroups: + - apps + verbs: + - update @@ (root level) @@ # rbac.authorization.k8s.io/v1/Role/rook-ceph/ceph-csi-nvmeof-nodeplugin-r ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: Role + metadata: + name: ceph-csi-nvmeof-nodeplugin-r + namespace: rook-ceph + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + rules: + - resources: + - csiaddonsnodes + apiGroups: + - csiaddons.openshift.io + verbs: + - get + - watch + - list + - create + - update + - delete + - resources: + - pods + apiGroups: + - + verbs: + - get + - resources: + - replicasets + apiGroups: + - apps + verbs: + - get + - resources: + - deployments/finalizers + - daemonsets/finalizers + apiGroups: + - apps + verbs: + - update @@ (root level) @@ # rbac.authorization.k8s.io/v1/Role/rook-ceph/ceph-csi-rbd-ctrlplugin-r ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: Role + metadata: + name: ceph-csi-rbd-ctrlplugin-r + namespace: rook-ceph + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + rules: + - resources: + - leases + apiGroups: + - coordination.k8s.io + verbs: + - get + - watch + - list + - delete + - update + - create + - resources: + - csiaddonsnodes + apiGroups: + - csiaddons.openshift.io + verbs: + - get + - watch + - list + - create + - update + - delete + - resources: + - pods + apiGroups: + - + verbs: + - get + - resources: + - replicasets + apiGroups: + - apps + verbs: + - get + - resources: + - deployments/finalizers + - daemonsets/finalizers + apiGroups: + - apps + verbs: + - update @@ (root level) @@ # rbac.authorization.k8s.io/v1/Role/rook-ceph/ceph-csi-rbd-nodeplugin-r ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: Role + metadata: + name: ceph-csi-rbd-nodeplugin-r + namespace: rook-ceph + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + rules: + - resources: + - csiaddonsnodes + apiGroups: + - csiaddons.openshift.io + verbs: + - get + - watch + - list + - create + - update + - delete + - resources: + - pods + apiGroups: + - + verbs: + - get + - resources: + - replicasets + apiGroups: + - apps + verbs: + - get + - resources: + - deployments/finalizers + - daemonsets/finalizers + apiGroups: + - apps + verbs: + - update @@ (root level) @@ # rbac.authorization.k8s.io/v1/Role/rook-ceph/cephfs-external-provisioner-cfg ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: Role + metadata: + name: cephfs-external-provisioner-cfg + namespace: rook-ceph + labels: + app.kubernetes.io/created-by: helm + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: rook-ceph + app.kubernetes.io/part-of: rook-ceph-operator + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + operator: rook + storage-backend: ceph + rules: + - resources: + - leases + apiGroups: + - coordination.k8s.io + verbs: + - get + - watch + - list + - delete + - update + - create @@ (root level) @@ # rbac.authorization.k8s.io/v1/Role/rook-ceph/rbd-external-provisioner-cfg ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: Role + metadata: + name: rbd-external-provisioner-cfg + namespace: rook-ceph + labels: + app.kubernetes.io/created-by: helm + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: rook-ceph + app.kubernetes.io/part-of: rook-ceph-operator + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + operator: rook + storage-backend: ceph + rules: + - resources: + - leases + apiGroups: + - coordination.k8s.io + verbs: + - get + - watch + - list + - delete + - update + - create @@ (root level) @@ # rbac.authorization.k8s.io/v1/RoleBinding/rook-ceph/ceph-csi-cephfs-ctrlplugin-rb ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: RoleBinding + metadata: + name: ceph-csi-cephfs-ctrlplugin-rb + namespace: rook-ceph + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + roleRef: + name: ceph-csi-cephfs-ctrlplugin-r + apiGroup: rbac.authorization.k8s.io + kind: Role + subjects: + - name: ceph-csi-cephfs-ctrlplugin-sa + kind: ServiceAccount + namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/RoleBinding/rook-ceph/ceph-csi-cephfs-nodeplugin-rb ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: RoleBinding + metadata: + name: ceph-csi-cephfs-nodeplugin-rb + namespace: rook-ceph + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + roleRef: + name: ceph-csi-cephfs-nodeplugin-r + apiGroup: rbac.authorization.k8s.io + kind: Role + subjects: + - name: ceph-csi-cephfs-nodeplugin-sa + kind: ServiceAccount + namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/RoleBinding/rook-ceph/ceph-csi-nvmeof-ctrlplugin-rb ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: RoleBinding + metadata: + name: ceph-csi-nvmeof-ctrlplugin-rb + namespace: rook-ceph + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + roleRef: + name: ceph-csi-nvmeof-ctrlplugin-r + apiGroup: rbac.authorization.k8s.io + kind: Role + subjects: + - name: ceph-csi-nvmeof-ctrlplugin-sa + kind: ServiceAccount + namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/RoleBinding/rook-ceph/ceph-csi-nvmeof-nodeplugin-rb ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: RoleBinding + metadata: + name: ceph-csi-nvmeof-nodeplugin-rb + namespace: rook-ceph + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + roleRef: + name: ceph-csi-nvmeof-nodeplugin-r + apiGroup: rbac.authorization.k8s.io + kind: Role + subjects: + - name: ceph-csi-nvmeof-nodeplugin-sa + kind: ServiceAccount + namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/RoleBinding/rook-ceph/ceph-csi-rbd-ctrlplugin-rb ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: RoleBinding + metadata: + name: ceph-csi-rbd-ctrlplugin-rb + namespace: rook-ceph + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + roleRef: + name: ceph-csi-rbd-ctrlplugin-r + apiGroup: rbac.authorization.k8s.io + kind: Role + subjects: + - name: ceph-csi-rbd-ctrlplugin-sa + kind: ServiceAccount + namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/RoleBinding/rook-ceph/ceph-csi-rbd-nodeplugin-rb ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: RoleBinding + metadata: + name: ceph-csi-rbd-nodeplugin-rb + namespace: rook-ceph + labels: + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: ceph-csi + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + roleRef: + name: ceph-csi-rbd-nodeplugin-r + apiGroup: rbac.authorization.k8s.io + kind: Role + subjects: + - name: ceph-csi-rbd-nodeplugin-sa + kind: ServiceAccount + namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/RoleBinding/rook-ceph/cephfs-csi-provisioner-role-cfg ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: RoleBinding + metadata: + name: cephfs-csi-provisioner-role-cfg + namespace: rook-ceph + labels: + app.kubernetes.io/created-by: helm + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: rook-ceph + app.kubernetes.io/part-of: rook-ceph-operator + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + operator: rook + storage-backend: ceph + roleRef: + name: cephfs-external-provisioner-cfg + apiGroup: rbac.authorization.k8s.io + kind: Role + subjects: + - name: rook-csi-cephfs-provisioner-sa + kind: ServiceAccount + namespace: rook-ceph @@ (root level) @@ # rbac.authorization.k8s.io/v1/RoleBinding/rook-ceph/rbd-csi-provisioner-role-cfg ! + one document added: + apiVersion: rbac.authorization.k8s.io/v1 + kind: RoleBinding + metadata: + name: rbd-csi-provisioner-role-cfg + namespace: rook-ceph + labels: + app.kubernetes.io/created-by: helm + app.kubernetes.io/instance: rook-ceph + app.kubernetes.io/managed-by: Helm + app.kubernetes.io/name: rook-ceph + app.kubernetes.io/part-of: rook-ceph-operator + helm.toolkit.fluxcd.io/name: rook-ceph + helm.toolkit.fluxcd.io/namespace: rook-ceph + operator: rook + storage-backend: ceph + roleRef: + name: rbd-external-provisioner-cfg + apiGroup: rbac.authorization.k8s.io + kind: Role + subjects: + - name: rook-csi-rbd-provisioner-sa + kind: ServiceAccount + namespace: rook-ceph ``` </details> <sub>Diff created by [flate](https://github.com/home-operations/flate) — [Workflow run](https://git.dcunha.io/Exikle/Artemis-Cluster/actions/runs/804)</sub>
Exikle merged commit bdb73160bf into main 2026-06-04 04:54:10 +00:00
Exikle deleted branch renovate-ghcr.io-pocket-id-pocket-id-2.x 2026-06-04 04:54:10 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
Exikle/Artemis-Cluster!222
No description provided.