Minimal RBAC manifests for backup agents that need to snapshot and restore virtual machines on OpenShift Virtualization (KubeVirt). No cluster-admin required.
This repository accompanies the blog post: Why Your Backup Agent Should Never Get Cluster-Admin
# 1. Apply cluster-scoped resources (namespace, SA, ClusterRole, ClusterRoleBinding)
oc apply -k base/
# 2. Apply namespace-scoped Role to each VM namespace
# Copy overlays/example/ and change the namespace
cp -r overlays/example overlays/my-vms
sed -i 's/my-vms/YOUR_NAMESPACE/' overlays/my-vms/kustomization.yaml
oc apply -k overlays/my-vms/
# 3. Verify permissions
chmod +x tests/verify.sh
./tests/verify.sh YOUR_NAMESPACE
# 4. (Optional) Run end-to-end snapshot test
chmod +x tests/e2e-snapshot.sh
./tests/e2e-snapshot.sh YOUR_NAMESPACE YOUR_VM_NAME.
├── base/ # Cluster-scoped resources
│ ├── kustomization.yaml
│ ├── namespace.yaml # backup-agent namespace
│ ├── serviceaccount.yaml # backup-agent SA
│ ├── clusterrole.yaml # Read: PVs, nodes, SC, VSC, CDI. Write: VSContents
│ ├── clusterrolebinding.yaml
│ ├── role.yaml # Per-namespace: VMs, snapshots, PVCs, events
│ └── rolebinding.yaml
├── overlays/
│ └── example/ # Copy and customize per namespace
│ └── kustomization.yaml
├── acm-policy/
│ └── backup-vm-rbac-policy.yaml # ACM Policy for multi-cluster distribution
├── tests/
│ ├── verify.sh # RBAC permission matrix test
│ └── e2e-snapshot.sh # End-to-end snapshot workflow test
└── README.md
| Resource | Verbs | Reason |
|---|---|---|
persistentvolumes |
get, list, watch | Storage topology discovery |
nodes |
get, list, watch | Infrastructure context |
storageclasses |
get, list, watch | Snapshot class selection |
cdis |
get, list, watch | CDI capability detection |
volumesnapshotclasses |
get, list, watch | Snapshot class discovery |
volumesnapshotcontents |
get, list, watch, create, update, patch, delete | Snapshot data lifecycle |
| Resource | Verbs | Reason |
|---|---|---|
virtualmachines |
get, list, watch | Backup target discovery |
virtualmachineinstances |
get, list, watch | Running VM status |
virtualmachinesnapshots |
get, list, watch, create, update, patch, delete | Snapshot lifecycle |
virtualmachinesnapshotcontents |
get, list, watch, create, update, patch, delete | Snapshot data |
virtualmachinerestores |
get, list, watch, create, update, patch, delete | Restore lifecycle |
persistentvolumeclaims |
get, list, watch | Disk topology |
datavolumes |
get, list, watch | CDI disk discovery |
volumesnapshots |
get, list, watch, create, update, patch, delete | Volume snapshot lifecycle |
configmaps |
get, list, watch | Namespace config |
events |
get, list, watch, create | Audit trail |
secretsin any namespacepods,deployments,replicasetsnamespaces(list/create/delete)clusterroles,clusterrolebindings(read or write)virtualmachines(write/update/delete)volumesnapshotclasses(create/delete)
If you use Red Hat Advanced Cluster Management, apply the policy in acm-policy/:
oc apply -f acm-policy/backup-vm-rbac-policy.yamlThis distributes the namespace-scoped Role to all clusters labeled has-openshift-virtualization: "true", in namespaces labeled workload-type: virtualization.
- OpenShift 4.20 with OpenShift Virtualization 4.20
- CSI drivers: Ceph RBD, Hitachi HSPC
- Snapshot API:
snapshot.kubevirt.io/v1beta1
Apache License 2.0