NO-ISSUE: sync kustomize manifest AuthConfig Rego with Helm chart - #525
Conversation
The AuthConfig Rego policy in manifests/base/ diverged from the Helm chart in charts/service/. PR #498 added organization-scoped authorization (tenant admin roles, subject tenants, realm roles, has_client_permissions) to the Helm chart but not to the kustomize manifests. Environments deployed via osac-installer used the stale manifest, causing OSAC-807. This syncs the manifest with the Helm chart by adding: - tenant_admin_roles and tenant_idp_manager_roles - subject_tenants resolution from JWT organization claims - subject_realm_roles from realm_access.roles - is_tenant_admin and is_tenant_idp_manager checks - has_client_permissions (union of client + tenant roles) - Users API allow rules for tenant admins - Roles/RoleBindings Get/List in client allowlist - Response section: use subject_tenants instead of groups Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
|
@omer-vishlitzky: This pull request explicitly references no jira issue. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
Warning Rate limit exceeded
You’ve run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: adriengentil, jhernand, omer-vishlitzky The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Summary
The AuthConfig Rego policy in
manifests/base/grpc-server/authconfig.yaml(used by osac-installer kustomize deployments) diverged from the Helm chart atcharts/service/templates/grpc-server/authconfig.yaml(used by integration tests). This caused OSAC-807: environments deployed via osac-installer had a stale authorization policy that broke JWT authentication.Specifically, PR #498 (OSAC-478: Add Organization-scoped authorization for Admins) added organization-scoped authorization to the Helm chart but not to the kustomize manifests. The integration tests passed because they test against the Helm chart. The E2E tests passed because they authenticate as K8s service accounts which bypass the broken JWT code path.
This PR syncs the kustomize manifest with the Helm chart by adding the missing Fine-Grained Authorization Policy rules.
What's added to the Rego policy
tenant_admin_roles{tenant-admin, tenant-user-manager}tenant_idp_manager_roles{tenant-admin, tenant-idp-manager}subject_tenantsorganization/organizationsclaims with group fallbacksubject_realm_rolesrealm_access.rolesis_tenant_adminis_tenant_idp_managerhas_client_permissionsis_client,is_tenant_admin,is_tenant_idp_manageris_client(updated)has_client_permissionsinstead ofis_clientResponse section fix
The
tenantsexpression in thex-subjectresponse header now usesauth.authorization.default.subject_tenants(from the OPA result) instead ofauth.identity.groups(raw JWT claim). This matches the Helm chart and ensures correct tenant scoping for JWT users.Test plan
ginkgo run -r internal🤖 Generated with Claude Code