From 29edb7b328115b8587c275b18f00c3fa53529b59 Mon Sep 17 00:00:00 2001 From: Casey Davenport Date: Thu, 21 May 2026 13:46:39 -0700 Subject: [PATCH] Grant calico-apiserver RBAC for managedclusters/status Without this, voltron's status updates fail when the aggregated apiserver proxies the write through to the backing CRD as its own service account. --- pkg/render/apiserver.go | 1 + 1 file changed, 1 insertion(+) diff --git a/pkg/render/apiserver.go b/pkg/render/apiserver.go index fa2fe4fd45..ac685a91a6 100644 --- a/pkg/render/apiserver.go +++ b/pkg/render/apiserver.go @@ -1448,6 +1448,7 @@ func (c *apiServerComponent) tigeraAPIServerClusterRole() *rbacv1.ClusterRole { "globalthreatfeeds/status", "licensekeys", "managedclusters", + "managedclusters/status", "networks", "packetcaptures", "policyrecommendationscopes",