Skip to content

[release-v1.42] Add HEP-related RBAC for policy recommendation#4594

Merged
rene-dekker merged 1 commit intotigera:release-v1.42from
xiumozhan:ev-6494-cherry-pick-4565-release-v1.42
Mar 25, 2026
Merged

[release-v1.42] Add HEP-related RBAC for policy recommendation#4594
rene-dekker merged 1 commit intotigera:release-v1.42from
xiumozhan:ev-6494-cherry-pick-4565-release-v1.42

Conversation

@xiumozhan
Copy link
Contributor

Summary

Cherry-pick of #4565 to release-v1.42.

  • Add stagedglobalnetworkpolicies, tier.stagedglobalnetworkpolicies, globalnetworkpolicies, tier.globalnetworkpolicies, and hostendpoints to the tigera-policy-recommendation ClusterRole
  • The host endpoint policy recommendation engine needs these permissions to create and manage recommended staged global network policies for non-cluster hosts

Test plan

  • CI passes on release-v1.42

Release Note

Give Policy Recommendation Controller the necessary RBAC to recommend policies for HostEndpoints.

🤖 Generated with Claude Code

The host endpoint policy recommendation engine needs access to
stagedglobalnetworkpolicies, globalnetworkpolicies, and hostendpoints
resources (including their tier-scoped variants) to create and manage
recommended policies for non-cluster hosts.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@rene-dekker rene-dekker merged commit 7ea2b48 into tigera:release-v1.42 Mar 25, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants