Skip to content
This repository was archived by the owner on Sep 9, 2026. It is now read-only.

NO-ISSUE: sync kustomize manifest AuthConfig Rego with Helm chart - #525

Merged
openshift-merge-bot[bot] merged 1 commit into
mainfrom
sync-manifest-authconfig-with-helm
May 13, 2026
Merged

openshift-merge-bot[bot] merged 1 commit into
mainfrom
sync-manifest-authconfig-with-helm

Conversation

@omer-vishlitzky

@omer-vishlitzky omer-vishlitzky commented May 13, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The AuthConfig Rego policy in manifests/base/grpc-server/authconfig.yaml (used by osac-installer kustomize deployments) diverged from the Helm chart at charts/service/templates/grpc-server/authconfig.yaml (used by integration tests). This caused OSAC-807: environments deployed via osac-installer had a stale authorization policy that broke JWT authentication.

Specifically, PR #498 (OSAC-478: Add Organization-scoped authorization for Admins) added organization-scoped authorization to the Helm chart but not to the kustomize manifests. The integration tests passed because they test against the Helm chart. The E2E tests passed because they authenticate as K8s service accounts which bypass the broken JWT code path.

This PR syncs the kustomize manifest with the Helm chart by adding the missing Fine-Grained Authorization Policy rules.

What's added to the Rego policy

Rule Purpose
tenant_admin_roles {tenant-admin, tenant-user-manager}
tenant_idp_manager_roles {tenant-admin, tenant-idp-manager}
subject_tenants Resolves tenant from JWT organization/organizations claims with group fallback
subject_realm_roles Extracts realm roles from JWT realm_access.roles
is_tenant_admin Checks if user has a tenant admin role
is_tenant_idp_manager Checks if user has a tenant IdP manager role
has_client_permissions Union of is_client, is_tenant_admin, is_tenant_idp_manager
is_client (updated) Now excludes tenant admins and IdP managers
Users API allow Tenant admins can CRUD Users
Client allow (updated) Uses has_client_permissions instead of is_client
Roles/RoleBindings Added Get/List to client allowlist

Response section fix

The tenants expression in the x-subject response header now uses auth.authorization.default.subject_tenants (from the OPA result) instead of auth.identity.groups (raw JWT claim). This matches the Helm chart and ensures correct tenant scoping for JWT users.

Test plan

  • Integration tests pass: ginkgo run -r internal
  • Diff between Helm chart (with template vars resolved) and manifest shows only expected differences (template syntax, namespace defaults)
  • Prow E2E tests pass

🤖 Generated with Claude Code

The AuthConfig Rego policy in manifests/base/ diverged from the Helm
chart in charts/service/. PR #498 added organization-scoped authorization
(tenant admin roles, subject tenants, realm roles, has_client_permissions)
to the Helm chart but not to the kustomize manifests. Environments
deployed via osac-installer used the stale manifest, causing OSAC-807.

This syncs the manifest with the Helm chart by adding:
- tenant_admin_roles and tenant_idp_manager_roles
- subject_tenants resolution from JWT organization claims
- subject_realm_roles from realm_access.roles
- is_tenant_admin and is_tenant_idp_manager checks
- has_client_permissions (union of client + tenant roles)
- Users API allow rules for tenant admins
- Roles/RoleBindings Get/List in client allowlist
- Response section: use subject_tenants instead of groups

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@openshift-ci-robot

openshift-ci-robot commented May 13, 2026 •

Copy link
Copy Markdown

@omer-vishlitzky: This pull request explicitly references no jira issue.

Details

In response to this:

Summary

The AuthConfig Rego policy in manifests/base/grpc-server/authconfig.yaml (used by osac-installer kustomize deployments) diverged from the Helm chart at charts/service/templates/grpc-server/authconfig.yaml (used by integration tests). This caused OSAC-807: environments deployed via osac-installer had a stale authorization policy that broke JWT authentication.

Specifically, PR #498 (OSAC-478: Add Organization-scoped authorization for Admins) added organization-scoped authorization to the Helm chart but not to the kustomize manifests. The integration tests passed because they test against the Helm chart. The E2E tests passed because they authenticate as K8s service accounts which bypass the broken JWT code path.

This PR syncs the kustomize manifest with the Helm chart by adding the missing FGAP (Fine-Grained Authorization Policy) rules.

What's added to the Rego policy

Rule Purpose
tenant_admin_roles {tenant-admin, tenant-user-manager}
tenant_idp_manager_roles {tenant-admin, tenant-idp-manager}
subject_tenants Resolves tenant from JWT organization/organizations claims with group fallback
subject_realm_roles Extracts realm roles from JWT realm_access.roles
is_tenant_admin Checks if user has a tenant admin role
is_tenant_idp_manager Checks if user has a tenant IdP manager role
has_client_permissions Union of is_client, is_tenant_admin, is_tenant_idp_manager
is_client (updated) Now excludes tenant admins and IdP managers
Users API allow Tenant admins can CRUD Users
Client allow (updated) Uses has_client_permissions instead of is_client
Roles/RoleBindings Added Get/List to client allowlist

Response section fix

The tenants expression in the x-subject response header now uses auth.authorization.default.subject_tenants (from the OPA result) instead of auth.identity.groups (raw JWT claim). This matches the Helm chart and ensures correct tenant scoping for JWT users.

Test plan

  • Integration tests pass: ginkgo run -r internal
  • Diff between Helm chart (with template vars resolved) and manifest shows only expected differences (template syntax, namespace defaults)
  • Prow E2E tests pass

🤖 Generated with Claude Code

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci
openshift-ci Bot requested review from jhernand and trewest May 13, 2026 09:31
@coderabbitai

coderabbitai Bot commented May 13, 2026

Copy link
Copy Markdown

Warning

Rate limit exceeded

@omer-vishlitzky has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 59 minutes and 18 seconds before requesting another review.

You’ve run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 96fd42f0-aa22-4116-a443-6a3831d83cb2

📥 Commits

Reviewing files that changed from the base of the PR and between cac6ad1 and 430bf65.

📒 Files selected for processing (1)
  • manifests/base/grpc-server/authconfig.yaml
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch sync-manifest-authconfig-with-helm

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@openshift-ci

openshift-ci Bot commented May 13, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: adriengentil, jhernand, omer-vishlitzky

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:
  • OWNERS [adriengentil,jhernand,omer-vishlitzky]

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-bot
openshift-merge-bot Bot merged commit 19d1191 into main May 13, 2026
13 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants