impersonation proxy: add RBAC to impersonate user extra and SAs
Signed-off-by: Monis Khan <mok@vmware.com>
This commit is contained in:
parent
b6e217e13a
commit
2179c2879a
@ -32,7 +32,10 @@ rules:
|
|||||||
verbs: [ use ]
|
verbs: [ use ]
|
||||||
resourceNames: [ nonroot ]
|
resourceNames: [ nonroot ]
|
||||||
- apiGroups: [ "" ]
|
- apiGroups: [ "" ]
|
||||||
resources: [ "users", "groups" ]
|
resources: [ "users", "groups", "serviceaccounts" ]
|
||||||
|
verbs: [ "impersonate" ]
|
||||||
|
- apiGroups: [ "authentication.k8s.io" ]
|
||||||
|
resources: [ "*" ] #! What we really want is userextras/* but the RBAC authorizer only supports */subresource, not resource/*
|
||||||
verbs: [ "impersonate" ]
|
verbs: [ "impersonate" ]
|
||||||
- apiGroups: [ "" ]
|
- apiGroups: [ "" ]
|
||||||
resources: [ nodes ]
|
resources: [ nodes ]
|
||||||
|
Loading…
Reference in New Issue
Block a user