From 7a6902b5cb31f91d5f1c7d30336305db4ac32083 Mon Sep 17 00:00:00 2001 From: Mykola Dobush Date: Mon, 28 Sep 2026 11:40:17 +0300 Subject: [PATCH] fix(iam): grant org viewers read on the service catalog MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit datumctl plugins that gate on service activation (compute, and any future plugin adopting the same SDK) list Service objects in the platform-wide catalog before running, to read the live entitlement mode instead of a hard-coded copy. No assignable role granted that read: owner, editor and viewer all inherited services.miloapis.com-entitlement-viewer/-admin (ServiceEntitlement, ServiceConsumer, ServiceAvailability) but never the sibling services.miloapis.com-viewer role that covers the Service resource itself. Every caller that goes through the Role/PolicyBinding system — service accounts in particular — got Forbidden on that lookup, regardless of role. Add services.miloapis.com-viewer next to the existing entitlement-viewer grant. Editor and owner both inherit viewer, so this reaches every assignable organization role from one place, matching how the other per-service viewer roles are wired in this file. --- .../assignable-organization-roles/roles/datum-cloud-viewer.yaml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/config/assignable-organization-roles/roles/datum-cloud-viewer.yaml b/config/assignable-organization-roles/roles/datum-cloud-viewer.yaml index d530462..f4183fb 100644 --- a/config/assignable-organization-roles/roles/datum-cloud-viewer.yaml +++ b/config/assignable-organization-roles/roles/datum-cloud-viewer.yaml @@ -36,6 +36,8 @@ spec: namespace: milo-system - name: billing.miloapis.com-viewer namespace: milo-system + - name: services.miloapis.com-viewer + namespace: milo-system - name: services.miloapis.com-entitlement-viewer namespace: milo-system - name: compute.datumapis.com-viewer