-
Notifications
You must be signed in to change notification settings - Fork 116
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
kubernetes rbac rules not enforced #3694
Comments
When we first added k8s inside Docker Desktop, we added a rule to promote all service accounts to be cluster admin. It helps people who install helm to start easily and to forget security. Maybe it's time to remove it (or at least make it optional). Can you try to delete the ClusterRoleBinding named Thanks |
wow, thanks! confirmed that deleting this binding fixes the issue. |
In the last stable and edge, we changed the rule to only affect the |
hello, if i want to restore the clusterrolebindings docker-for-desktop-binding, what is the spec? |
@pluckhuang if you want to restore the apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: docker-for-desktop-binding
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: cluster-admin
subjects:
- apiGroup: rbac.authorization.k8s.io
kind: Group
name: system:serviceaccounts
namespace: kube-system |
The problem still exists in Docker for desktop version: 2.2.0.5(43884)
and not
|
Closed issues are locked after 30 days of inactivity. If you have found a problem that seems similar to this, please open a new issue. Send feedback to Docker Community Slack channels #docker-for-mac or #docker-for-windows. |
Steps to reproduce the behavior
https://jeremievallee.com/2018/05/28/kubernetes-rbac-namespace-user.html
Expected behavior
Expected behavior: Kubernetes should deny access
Actual behavior
Kubernetes allows access
Information
This works correctly with all other Kubernetes clusters I've tried, just not the one packaged with DockerForMac. Is there any chance you've disabled RBAC somehow?
I'm happy to write up a more complete bash script to reproduce the issue, but wanted to make sure this wasn't a known issue.
The text was updated successfully, but these errors were encountered: