)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"f17bb0825591a5f56b42827d94549e9757cd029b","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"b7e61f37_ebdc6f89","updated":"2025-08-13 23:40:24.000000000","message":"Doesn\u0027t look like any of the other k8s like provider drivers manipulate apiGroups permissions.","commit_id":"260c0e04e6cc4d44b874dcb4b575f50525b2361a"},{"author":{"_account_id":37264,"name":"Ruisi Jian","display_name":"Sissi","email":"rjian@arista.com","username":"rjian"},"change_message_id":"d152df21937f87b9fcab5e8250e2244c12e3996a","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"4ab6b491_1a846ab5","updated":"2025-06-24 16:32:26.000000000","message":"Hi,\n\nWe just started to get blocked by this bug when we tried to remove the cluster-admin privilege for service accounts due to security reasons. As the global cluster-admin binding was removed, this zuul Role start actually being enforced. And the misconfigured resources will result in Forbidden 403 error when we tried to create a kubernetes job in the created namespace. (We have tested this fix locally by building/using a nodepool-launcher image that has this fix and it resolves the Forbidden 403 errors when cluster-admin privilege is removed for service accounts.) Could we get this fix proceed in the merging process?\n\nThank you.","commit_id":"260c0e04e6cc4d44b874dcb4b575f50525b2361a"}]}
