Skip to content

fix(scripts): compare ClusterRole rules by API group, resource and verb in the drift check - #108

Merged
tim-thacker-nullify merged 2 commits into
mainfrom
fix/drift-check-compares-api-groups
Sep 27, 2026
Merged

tim-thacker-nullify merged 2 commits into
mainfrom
fix/drift-check-compares-api-groups

Conversation

@tim-thacker-nullify

@tim-thacker-nullify tim-thacker-nullify commented Sep 27, 2026 •

Copy link
Copy Markdown
Member

Claude

scripts/check_iam_policy_drift.py compared ClusterRole rules by resource name only, so a kind moved to the wrong API group (e.g. gateways under networking.istio.io instead of gateway.networking.k8s.io) passed.

  • Compare ClusterRole rules as (API group, resource, verb) triples, and fail on a rule the parser cannot read.
  • Fix the Helm comparison's mismatch message, which said "CloudFormation".
  • Correct the Terraform README "Kinds read" cell, which predated the current kind list.

Proposed grants for mesh, Gateway API and network-policy CRDs are held back until the collector lists those kinds; granting permissions nothing calls widens customer access for no gain.

🤖 Generated with Claude Code


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

tim-thacker-nullify and others added 2 commits September 27, 2026 15:51
…rb in the drift check

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@tim-thacker-nullify
tim-thacker-nullify marked this pull request as ready for review September 27, 2026 07:14
@tim-thacker-nullify
tim-thacker-nullify merged commit c5f0501 into main Sep 27, 2026
29 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants