Fix profiler discovery permissions for the observability project #67
Loading…
Reference in a new issue
No description provided.
Delete branch "codex/profiler-discovery-rbac-20260909"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Argo CD refused Roles in the three application namespaces, so the profiler could not start. Use one pod-read-only ClusterRole and bind the dedicated profiler account. Keep discovery filtered to the three canary namespaces.
Validation: Kubernetes server dry-run; all Olly checks. No Secret access is granted.