# Run elastic-operator with fewer permissions? Disable webhook?

**URL:** <https://discuss.elastic.co/t/run-elastic-operator-with-fewer-permissions-disable-webhook/217135>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [January 30, 2020, 9:02am UTC](https://discuss.elastic.co/t/run-elastic-operator-with-fewer-permissions-disable-webhook/217135 "2020-01-30T09:02:15Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![CoaxVex](https://avatars.discourse-cdn.com/v4/letter/c/ac91a4/32.png) [@CoaxVex](https://discuss.elastic.co/u/CoaxVex)\
**Post date:** [January 30, 2020, 9:02am UTC](https://discuss.elastic.co/t/run-elastic-operator-with-fewer-permissions-disable-webhook/217135/1 "2020-01-30T09:02:15Z")

</div>

The elastic-operator ClusterRole, which is deployed and granted when installing with the "all-in-one.yaml" method gives a lot of permissions on the cluster. So much even, you may as well be running the operator as cluster-admin.

Is there a supported deployment method which allows the operator to run so that it can only watch / manage objects in specific namespaces?

Can we also go without permissions to manage admission configurations? (ie: disable the webhook?) I do not feel comfortable sending all my secrets to the operator for inspection, and it makes the uninstalls more complex...

---

<div class="post-metadata">

**Author:** ![pebrc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pebrc/32/101790_2.png) [@pebrc](https://discuss.elastic.co/u/pebrc)\
**Post date:** [January 30, 2020, 9:31am UTC](https://discuss.elastic.co/t/run-elastic-operator-with-fewer-permissions-disable-webhook/217135/2 "2020-01-30T09:31:03Z")

</div>

> Is there a supported deployment method which allows the operator to run so that it can only watch / manage objects in specific namespaces?

Yes, you can configure the operator to only manage objects in a single namespace or a set of namespaces. Have a look at the `--namespaces` argument in [Configure ECK | Elastic Cloud on Kubernetes [master] | Elastic](https://www.elastic.co/guide/en/cloud-on-k8s/master/k8s-operator-config.html)

> Can we also go without permissions to manage admission configurations? (ie: disable the webhook?)

Yes that is also possible, you will have to to change the `--roles` argument of the operator from `all` to `global,namespace`. You can then reduce the RBAC permissions you give to the `elastic-operator` service account.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 7:42am UTC](https://discuss.elastic.co/t/run-elastic-operator-with-fewer-permissions-disable-webhook/217135/3 "2022-11-04T07:42:47Z")

</div>


