Skip to content

[cloudnative-pg] Feature - Support RBAC per watched namespace #873

@maltelehmann

Description

@maltelehmann

I would like to restrict access of the CNPG to a list of namespaces while minimizing cluster wide permissions. The aim is to follow the principle of least priviledge.

Currently, it is only possible to get cluster wide RBAC and limit the namespaces using the WATCH_NAMESPACE variable, or get single nsmespace RBACs. It would be nice to have the choice between cluster wide, multi namespace and single namespace.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions