kubernetes-sigs/cluster-api

Minimize RBAC roles for controllers

开放

#6,554 创建于 2022年5月26日

 (14 条评论) (1 个反应) (1 位负责人)Go (1,532 个派生)auto 404
help wantedkind/cleanuppriority/important-longtermtriage/accepted

仓库指标

星标
 (4,267 个星标)
PR 合并指标
 (PR 指标待抓取)

描述

Following on from #https://github.com/kubernetes-sigs/cluster-api/pull/6510#discussion_r882538225

In Cluster API today we create RBAC manifests which are generated using kubebuilder tools. e.g.

https://github.com/kubernetes-sigs/cluster-api/blob/626ab4de03ef1e8f9b68e12bbfaf75e2cb0b4ffc/internal/controllers/clusterclass/clusterclass_controller.go#L42-L44

Many of our controllers seem to generate overly broad RBAC for themselves. e.g. many have the create verb when it is not used. Removing these roles should have no impact on functitonality, minimize the capabilities of our controllers from a security perspective, and make our RBAC manifests more descriptive about what our controllers are actually doing.

We should audit the following controllers to minimize their RBAC roles:

  • MachineHealthCheck
  • Machinepool
  • KubeadmConfig
  • ClusterResourceSet
  • Cluster
  • Machine
  • MachineDeployment
  • MachineSet
  • Topology/Cluster
  • ClusterClass

贡献者指南