kubernetes-sigs/cluster-api

Minimize RBAC roles for controllers

開放

#6,554 建立於 2022年5月26日

 (14 則留言) (1 個反應) (1 位負責人)Go (1,532 個分叉)auto 404
help wantedkind/cleanuppriority/important-longtermtriage/accepted

倉庫指標

星標
 (4,267 顆星)
PR 合併指標
 (PR 指標待抓取)

描述

Following on from #https://github.com/kubernetes-sigs/cluster-api/pull/6510#discussion_r882538225

In Cluster API today we create RBAC manifests which are generated using kubebuilder tools. e.g.

https://github.com/kubernetes-sigs/cluster-api/blob/626ab4de03ef1e8f9b68e12bbfaf75e2cb0b4ffc/internal/controllers/clusterclass/clusterclass_controller.go#L42-L44

Many of our controllers seem to generate overly broad RBAC for themselves. e.g. many have the create verb when it is not used. Removing these roles should have no impact on functitonality, minimize the capabilities of our controllers from a security perspective, and make our RBAC manifests more descriptive about what our controllers are actually doing.

We should audit the following controllers to minimize their RBAC roles:

  • MachineHealthCheck
  • Machinepool
  • KubeadmConfig
  • ClusterResourceSet
  • Cluster
  • Machine
  • MachineDeployment
  • MachineSet
  • Topology/Cluster
  • ClusterClass

貢獻者指南