Full Kubernetes Agent (KRM) Permissions

IT Asset Management (Cloud)

Core permissions

  • Read-only access (get, list, watch) to nodes, namespaces, and pods.
  • Write access (create, delete, patch, update) for StatefulSets, DaemonSets, and Services.
  • Access to pods/exec for software inventory collection.

Optional permissions

  • OLM Support—Read-only access to resources like clusterserviceversions, catalogsources, installplans, subscriptions, and operatorgroups.
  • Storage Resources—Read-only access to persistentvolumes, persistentvolumeclaims, and storageclasses.
  • IBM Licensing:
    • Read-only access to IBM License Service API endpoints (for example, /products, /bundled_products, /snapshot, /health, /version) by way of the ibm-license-service-api-access ClusterRole.
    • Read-only access (get, list, watch) toibmlicensings Kubernetes resources via the flexera-krm-ibmlicensings ClusterRole.
  • Advanced Configurations—Access to configmaps for managing advanced configurations.
  • Security Context Constraints (SCC)—Access to the flexera-krm-scc resource for managing security context constraints in OpenShift environments.

IT Asset Management (Cloud)

Current