Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow administrator to list namespaces and manage RBACs and admission webhooks #2793

Merged
merged 1 commit into from Aug 31, 2020

Conversation

vpnachev
Copy link
Member

@vpnachev vpnachev commented Aug 28, 2020

How to categorize this PR?

/area ops-productivity user-management
/kind enhancement
/priority normal
/invite @donistz @mvladev

What this PR does / why we need it:
Allow landscape administrators to:

  1. have all permission to read all namespaces
  2. manage ClusterRole(Binding)s
  3. manage MutatingWebhookConfigurations and ValidatingWebhookConfigurations

Which issue(s) this PR fixes:
Fixes #

Special notes for your reviewer:

Release note:

`gardener.cloud:system:administrators` are now allowed to list namespaces, manage RBACs, admission webhooks and apiservices.

@vpnachev vpnachev requested a review from a team as a code owner August 28, 2020 13:39
@gardener-robot gardener-robot added area/ops-productivity Operator productivity related (how to improve operations) area/user-management User-management related kind/enhancement Enhancement, improvement, extension needs/review labels Aug 28, 2020
donistz
donistz previously approved these changes Aug 28, 2020
manage namespaces
manage RBACs
manage admission webhooks
manage apiservices
Copy link
Member

@timebertt timebertt left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@vpnachev vpnachev merged commit 51ee00b into gardener:master Aug 31, 2020
@vpnachev vpnachev deleted the rbac/adminstrator branch August 31, 2020 13:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/ops-productivity Operator productivity related (how to improve operations) area/user-management User-management related kind/enhancement Enhancement, improvement, extension
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

8 participants