Merge pull request #528 from enj/enj/i/impersonation-proxy-authz-user-extra

impersonation proxy: add RBAC to impersonate user extra and SAs
This commit is contained in:
Mo Khan
2021-03-26 00:37:24 -04:00
committed by GitHub

View File

@@ -32,7 +32,10 @@ rules:
verbs: [ use ]
resourceNames: [ nonroot ]
- apiGroups: [ "" ]
resources: [ "users", "groups" ]
resources: [ "users", "groups", "serviceaccounts" ]
verbs: [ "impersonate" ]
- apiGroups: [ "authentication.k8s.io" ]
resources: [ "*" ] #! What we really want is userextras/* but the RBAC authorizer only supports */subresource, not resource/*
verbs: [ "impersonate" ]
- apiGroups: [ "" ]
resources: [ nodes ]