mirror of
https://github.com/k3s-io/kubernetes.git
synced 2025-08-03 09:22:44 +00:00
Merge pull request #56095 from ericchiang/rbac-bootstrap-self-subject-rules-review
Automatic merge from submit-queue (batch tested with PRs 55112, 56029, 55740, 56095, 55845). If you want to cherry-pick this change to another branch, please follow the instructions <a href="https://github.com/kubernetes/community/blob/master/contributors/devel/cherry-picks.md">here</a>. rbac bootstrap policy: add selfsubjectrulesreviews to basic-user cc @kubernetes/sig-auth-pr-reviews Extracted from #53324, which wont be merged for 1.9. ```release-note The RBAC bootstrapping policy now allows authenticated users to create selfsubjectrulesreviews. ``` /assign @deads2k
This commit is contained in:
commit
678bad5170
@ -169,7 +169,7 @@ func ClusterRoles() []rbac.ClusterRole {
|
|||||||
ObjectMeta: metav1.ObjectMeta{Name: "system:basic-user"},
|
ObjectMeta: metav1.ObjectMeta{Name: "system:basic-user"},
|
||||||
Rules: []rbac.PolicyRule{
|
Rules: []rbac.PolicyRule{
|
||||||
// TODO add future selfsubjectrulesreview, project request APIs, project listing APIs
|
// TODO add future selfsubjectrulesreview, project request APIs, project listing APIs
|
||||||
rbac.NewRule("create").Groups(authorizationGroup).Resources("selfsubjectaccessreviews").RuleOrDie(),
|
rbac.NewRule("create").Groups(authorizationGroup).Resources("selfsubjectaccessreviews", "selfsubjectrulesreviews").RuleOrDie(),
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
|
|
||||||
|
@ -522,6 +522,7 @@ items:
|
|||||||
- authorization.k8s.io
|
- authorization.k8s.io
|
||||||
resources:
|
resources:
|
||||||
- selfsubjectaccessreviews
|
- selfsubjectaccessreviews
|
||||||
|
- selfsubjectrulesreviews
|
||||||
verbs:
|
verbs:
|
||||||
- create
|
- create
|
||||||
- apiVersion: rbac.authorization.k8s.io/v1
|
- apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
Loading…
Reference in New Issue
Block a user