-
Notifications
You must be signed in to change notification settings - Fork 4.8k
tighten authorization rules #1074
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
[test] |
|
continuous-integration/openshift-jenkins/test SUCCESS (https://ci.openshift.redhat.com/jenkins/job/test_pull_requests_openshift3/1196/) |
75a7967 to
2c64385
Compare
2c64385 to
f496dc5
Compare
|
@smarterclayton @liggitt fish or cut bait. |
|
2/3 on travis. |
|
So what README and documentation plans do you have changed so that once this happens every openshift user who tries it isn't broke? |
|
Currently, the readme has people using the cluster-admin id, so anyone following those steps continues to work. We already document how to add users to roles, those commands haven't changed. Is there another sample besides sample-app that people are using? I probably should write up documentation for |
|
Should update the help shown in the web UI when no projects exist to tell them to run |
Ok. I guess I'll also craft something for the mailing list and maybe add instructions to set up a user capable of viewing |
|
Doesnt the sample app use 'test'? |
|
It uses both. |
37294e7 to
ef444e2
Compare
|
@liggitt I updated the readme with a little more detail. Care to make sure it works for you? |
|
Not going to merge this until we cut another release image (v0.3.2) |
ef444e2 to
2cb77df
Compare
|
Rebased. Removed the readme updates since they were superceded by #1104 which can go in separately. |
|
Does everyone know this is coming and how to react? |
|
I'll send out a note now. |
Yes, everyone knows this is coming. Basic instructions were provided in an email and link to our more complete documentation was also provided. I also included information about gathering policy and bindings for bug reports (not that I think anything could possibly go wrong :) ) |
|
just noticed the Jenkins example isn't using identity yet (there's a bug open for cert validation errors, but identity would hit it also). Wondering if we should wait until we have a good way to inject a kubeconfig as a secret. |
|
Up to Ben
|
|
@bparees see above. |
|
Bug https://bugzilla.redhat.com/show_bug.cgi?id=1196022 found. Do not merge this until we get #1140 |
|
Not only do the jenkins setup steps need to be fixed to use identity, the jenkins job itself would need to have the certs (because it runs osc commands too) which it currently does not, so there's significant rework needed. (or use the --insecure flag, anyway, after doing an osc login or something). I haven't had a lot of people asking me questions about the jenkins example so my guess is it's not getting a lot of attention, but it would be nice to keep it working. |
It's currently broken, so it would be "make it work again". |
|
@deads2k is that the sound of volunteering i hear? |
|
It's definitely something people are looking at. Let's create a maint card if it still needs work after David's change.
|
|
I have a pr in progress to get it working again. That's where I hit the duplicate tag imagerepo issue. Ben Parees | OpenShift -----Original Message----- It's definitely something people are looking at. Let's create a maint card if it still needs work after David's change.
Reply to this email directly or view it on GitHub: |
2cb77df to
af1a6e3
Compare
af1a6e3 to
65d868f
Compare
|
reminder to myself to make sure we have the jenkins example working with secrets before merging this |
|
if we tighten this, the core path (master/node/registry/router) works, but other things like the Jenkins example will stop working until we can get identity info into it. We're planning to do that with secrets, but those won't be in origin until the rebase merges, and then there is some follow-up work to make creating a secret for Jenkins reasonable for an end-user. tl;dr - this can go in now if we accept things like the Jenkins example breaking until we get secret support into origin. |
|
That's fine with me
|
|
I saw the menion about jenkins in the comment. The beta training isn't making use of jenkins right now so I think we'd be OK. @thoraxe (let us know if you have concerns) |
|
I'm fine with Jenkins not working for beta2. |
|
pull the trigger! [merge] |
|
continuous-integration/openshift-jenkins/merge SUCCESS (https://ci.openshift.redhat.com/jenkins/job/merge_pull_requests_openshift3/1093/) (Image: devenv-fedora_954) |
|
Evaluated for origin up to 65d868f |
…service-catalog/' changes from 8f07b7b..7e650e7 7e650e7 origin build: add origin tooling f32eec2 unit test for ./pkg/rest/core/fake rest client, addresses openshift#860 Test ready to be reviewed (openshift#1113) e388aee explicitly always prefer latest OSBAPI Version (openshift#1138) 962429e Merge branch 'pr/1135' b6ee7ef fix rbac cb1beb9 Merge branch 'pr/1131' ecc5c01 Update Code of Conduct (openshift#1137) e7c5ab3 address one more PR comment ddcbbad address PR comments 652a83b fix test expectation to match the new error message for missing service class 33417cc address PR comments 565fccf Use the chart name instead of the namespace (openshift#1102) bc61919 Add new terminal failure binding condition (openshift#1057) 4e642d5 Added more detailed instructions on how to setup the repo (openshift#1114) bdaea23 update unit tests (openshift#1123) 88a9642 validate the apiserver options (openshift#1116) b0af5fc fix whitespace in the copyright section dee796a generated type changes ef585c4 Rename the directory from default to defaultservicename to conform to go style guide. Wire admission controller into the apiserver 0b5d6c6 add firewall troubleshooting section (openshift#1040) fd9e6bc Fix Typo in Events Code of Conduct (openshift#1126) ebe6506 Fix Typo in Terminology (openshift#1128) 0038b1e Merge branch 'pr/1122' 8411f31 make deprovisioning an instance asynchronously not fall-through to synchronous deprovision (openshift#1067) 76c1d93 handle failures from list and test the not ready condition, cleanup 9241296 finish unit tests, passing ed75774 Minor fixes based on go report card 9911e8d Add GoReport Widget (openshift#1121) dd24e5c clean up old cruft 08276c6 generated file changes 6489d90 Implement the default plan in admission controller a6bb576 Code: Instance/Binding parameters from secret (openshift#1079) 10bb148 Update generated files (openshift#1115) 5291e6f v0.0.15 (openshift#1118) 28a1ea6 Merge branch 'pr/1104' bb4a2d2 Merge branch 'pr/1097' 1c14a90 push all arch images on release tags (openshift#1108) b587b2c Improve log output for deprovision 8887561 Remove PodPreset embedding from Binding (openshift#1030) 1abdcc8 Adjust helm/tiller installation instructions (openshift#1091) f636f99 only skip tls verify if not behind the aggregator (openshift#1101) 43b40ab controller_broker unit test bullet-proofing openshift#1077 (openshift#1099) bb596b8 Use data store instead of database (openshift#1100) 04fa477 Implementation: Support for Bearer token auth between Service Catalog and brokers (openshift#1053) 9e46d3c refactor Jenkins e2e tests (openshift#1082) 1f0a41e remove old/misleading comments about only doing soft delete if it's "our turn--" i.e. only if the finalizer we care about is at the head of the finalizers list. 5c1d9b8 Update OSB client (openshift#1085) a6e80ea Only do work for instances from a single queue (openshift#1074) 2bd85d6 Merge branch 'pr/1076' e324287 Tweaks to the walkthrough for local-up-cluster d8b7899 Add a note to the walkthrough about getting bindings when using the aggregator (openshift#1078) ea44cf1 msg on Environment Variables to set for e2e (openshift#1070) d15554a Merge branch 'pr/1017' faf966e Add comment re: async race condition in integration tests ed2e096 v0.0.14 (openshift#1071) fc84ffd more PR feedback 283bed4 Add integration tests and some error checking; PR feedback 903a7a7 Add terminal condition for instance and do not retry failed provisions REVERT: 8f07b7b origin: add required patches git-subtree-dir: cmd/service-catalog/go/src/github.com/kubernetes-incubator/service-catalog git-subtree-split: 7e650e7e39c3fc79a8ecc061cce2a70e899406ff
Removes cluster-admin rights from system:authenticated and system:unauthenticated.