Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Much more granular RBAC permissions #86

Merged
merged 1 commit into from
May 16, 2019
Merged

Much more granular RBAC permissions #86

merged 1 commit into from
May 16, 2019

Conversation

robscott
Copy link
Contributor

This was quite the rabbit hole, and involved splitting up dashboard and webhook deploy components more to ensure that the dashboard didn't get any unnecessary access. I also ran into an interesting problem where deployments with a extensions api version were not getting intercepted by the webhook - this PR fixes that. Since controller-runtime's webhook component insists on logging to a file in /tmp, I ended up adding an emptyDir volume mount so we could continue to specify readOnlyRootFilesystem to ensure we're meeting our own standards here.

Copy link
Contributor

@rbren rbren left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good! Thanks for doing this Rob, looks like quite a rabbit hole. Definitely good that the dash has stricter permissions now

Corey/EJ may be able to catch something in the YAML that I'd miss, but so long as the dash and webhook are working properly I think we're safe to merge.

@robscott robscott merged commit ffe7f02 into master May 16, 2019
@robscott robscott deleted the rs/rbac branch May 16, 2019 14:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants