diff --git a/config/channels/in-memory-channel/roles/controller-clusterrole.yaml b/config/channels/in-memory-channel/roles/controller-clusterrole.yaml index 58c58143968..6164e834f41 100644 --- a/config/channels/in-memory-channel/roles/controller-clusterrole.yaml +++ b/config/channels/in-memory-channel/roles/controller-clusterrole.yaml @@ -53,15 +53,6 @@ rules: - get - list - watch - - apiGroups: - - sinks.knative.dev - resources: - - jobsinks - - jobsinks/status - verbs: - - get - - list - - watch - apiGroups: - "" resources: diff --git a/config/core/roles/addressable-resolvers-clusterrole.yaml b/config/core/roles/addressable-resolvers-clusterrole.yaml index 7bd948c7149..1f2ece335ef 100644 --- a/config/core/roles/addressable-resolvers-clusterrole.yaml +++ b/config/core/roles/addressable-resolvers-clusterrole.yaml @@ -144,3 +144,25 @@ rules: - get - list - watch + +--- + +kind: ClusterRole +apiVersion: rbac.authorization.k8s.io/v1 +metadata: + name: jobsinks-addressable-resolver + labels: + duck.knative.dev/addressable: "true" + app.kubernetes.io/version: devel + app.kubernetes.io/name: knative-eventing +# Do not use this role directly. These rules will be added to the "addressable-resolver" role. +rules: +- apiGroups: + - sinks.knative.dev + resources: + - jobsinks + - jobsinks/status + verbs: + - get + - list + - watch