[Feature]: Allow external RBAC configuration/dropping bootstrap-only RBAC permissions
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 25/100
Research direction
The payload names no files or tests, so the first step is locating where the operator creates its own RBAC objects at startup in the Go code. The issue asks for an opt-out toggle or env var, but the maintainers have not replied yet and the design is undecided, so agree on the approach in the thread before writing code. Done means RBAC management can be skipped without the operator crashing when it lacks permissions.
Written by the indexing model from the issue text.
Description
👋🏻
We've been looking at using gpu-operator to simplify some of our GPU infrastructure (and get rid of a couple of pain points at the same time!) - however, and, this might just be an us-problem: at $DAYJOB, we prefer to manage RBAC configurations ourselves/explicitly (i.e., have our own manifests in our gitops repo).
We looked into having our own ClusterRole/ClusterRoleBindings created and dropping any permissions that were unnecessary in our infra (or too broad and not required if the operator no longer needed them to bootstrap itself), but the operator currently doesn't expose a way to skip trying to manage its RBAC configs.
(i.e., we tried to do this, and were blocked by the operator crashing when it unconditionally tried to manage RBAC and whatnot on launch without the necessary permissions to do so :p)
As far as I can tell, there's no way to skip this code atm, so I'm totally happy to give implementing a feature toggle/env var/whatever a shot as long as y'all don't think this isn't a silly idea...but I figured y'all would want an issue/feature request first before talking about PRs/implementation :D
- Dominant language
- Go
- Stars
- 2.9k
- Forks
- 569
- Avg merge
- 1d 7h
- Merged PRs (30d)
- 76
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from NVIDIA/gpu-operator
-
[Bug]: Driver upgrade does not evict pods that use nvidia.com/gpu only in a native sidecarPossibly taken A pull request linked to this issue is open or already merged. Openbug needs-triage
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
NVIDIA/gpu-operator#3026 ·
Maintainers usually reply within 1 day
-
[Bug]: GPUCluster common name label breaks DRA validator selectorPossibly taken @ajavanma claimed this 18 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
NVIDIA/gpu-operator#2955 · 1 comment ·
Maintainers usually reply within 1 day
-
bug needs-triage
Difficulty 4/5 3-5 days Newbie friendliness 48/100
NVIDIA/gpu-operator#3027 ·
Maintainers usually reply within 1 day
-
Ensure automated backport commits have verified signaturesPossibly taken @asivanadi0 claimed this 9 days ago. Opengood-first-issue
Difficulty 4/5 3-5 days Newbie friendliness 55/100
NVIDIA/gpu-operator#2997 · 1 comment ·
Maintainers usually reply within 1 day
-
[Bug]: Latest Nvidia GPU Operator v26.7.1 reports large numbers of critical and high CVEs in Trivy scan outputPossibly taken @rahulait claimed this 10 days ago. Openmore-information-needed needs-triage
NVIDIA/gpu-operator#2991 · 3 comments · 1 assignee ·
Maintainers usually reply within 1 day
All issues in NVIDIA/gpu-operator
Similar issues
-
bug frontend good first issue
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 82/100
oalders/clodhopper#133 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
peasant-labs/peasant#596 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
hatchet-dev/hatchet#5179 ·
Maintainers usually reply within 1 day
-
bug triage
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
FairwindsOps/nova#484 ·