Skip to content

[archer] use dedicated ServiceAccount instead of namespace default - #12826

Merged
notandy merged 1 commit into
masterfrom
C5384329/archcher-sa
Oct 5, 2026
Merged

notandy merged 1 commit into
masterfrom
C5384329/archcher-sa

Conversation

@s10

@s10 s10 commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor
  • archer kubernets-entrypoint-containing pods use the default ServiceAccount, which no longer has cluster-reader RBAC, so dependency checks would fail
  • enable serviceAccount.create to always create archer SA
  • bump chart version to 0.1.4

- archer entrypoint pods fell back to the default SA, which no longer
  has cluster-reader RBAC, so dependency checks would be denied
- enable serviceAccount.create to render the SA/Role/RoleBinding and
  bind all workloads to it
- bump chart version to 0.1.4
@s10
s10 marked this pull request as ready for review September 23, 2026 09:58

@notandy notandy left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I already fixed the issue a pr in secrets repository enabling the service account in all regions, but it makes sense to enable it globally

@notandy
notandy merged commit 58a6289 into master Oct 5, 2026
3 checks passed
@notandy
notandy deleted the C5384329/archcher-sa branch October 5, 2026 18:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants