Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Sketch out design idea "identity unification" between kcp and physical clusters #26

Closed
smarterclayton opened this issue Apr 21, 2021 · 3 comments
Labels
new-investigation A topic that seems likely to be an area of investigation

Comments

@smarterclayton
Copy link
Contributor

smarterclayton commented Apr 21, 2021

Needs to cover the features a user might want like:

  • From kcp you can create a service account that pods running on physical clusters are associated with
  • A kcp service account token of some form can be created? (so that you can easily define identities not bound to the fate of a cluster)
  • Services from off cluster could potentially be integrated behind or via proxying of that identity (i.e. service account = global service identity = integrations that allow traffic going off cluster through a mesh can use that identity to authenticate)

And discuss the various efforts in the space like SPIFFE, ory, the cloud identity solutions, how someone could accumulate their own and expose via a mesh/egress proxy, etc.

@smarterclayton smarterclayton added the new-investigation A topic that seems likely to be an area of investigation label May 7, 2021
@ncdc
Copy link
Member

ncdc commented Feb 23, 2022

How (if at all) does this relate to #206? Partial/total duplicate?

@sttts sttts added this to the TBD milestone Jun 14, 2022
@ncdc ncdc removed this from the TBD milestone Oct 17, 2022
@mjudeikis
Copy link
Contributor

/close
not in scope for now. Will reopen if needed

@kcp-ci-bot
Copy link
Contributor

@mjudeikis: Closing this issue.

In response to this:

/close
not in scope for now. Will reopen if needed

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
new-investigation A topic that seems likely to be an area of investigation
Projects
Status: Done
Development

No branches or pull requests

5 participants