-
Notifications
You must be signed in to change notification settings - Fork 38.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
allow */subresource in rbac policy rules #53722
allow */subresource in rbac policy rules #53722
Conversation
/assign liggitt |
pkg/apis/rbac/helpers.go
Outdated
if len(requestedSubresource) == 0 { | ||
continue | ||
} | ||
ruleTokens := strings.SplitN(ruleResource, "/", 2) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
no allocations here, this is a hot spot.
if len(ruleResource) == len(requestedSubresource) + 2 && strings.HasPrefix(ruleResource, "*/") && strings.HasSuffix(ruleResource, requestedSubresource)
b648119
to
3a64f8c
Compare
allocations removed, readability reduced. |
/lgtm cc @DirectXMan12 for HPA updates. |
needs a release note |
Update the godoc on PolicyRule.Resources:
also update docs for ResourceRule.Resources (in authorization.k8s.io) |
cc @kubernetes/sig-auth-api-reviews |
/lgtm Not a super big fan of the idea, but I can see how it would be useful. |
3a64f8c
to
bb5b66d
Compare
bb5b66d
to
8cc1213
Compare
Allocs removed, release note added, updated godoc (and removed use of "ResourceAll"), updated default RBAC role. /lgtm |
@liggitt good minus regeneration? |
8cc1213
to
e8a703b
Compare
regenerated |
allows for polymorphic subresource authorization, consistent with admission syntax
/lgtm |
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: deads2k, enj, ericchiang, liggitt Assign the PR to them by writing Associated issue: 29698 The full list of commands accepted by this bot can be found here.
Needs approval from an approver in each of these OWNERS Files:
You can indicate your approval by writing |
last remain package is docs. That was generated. tagging approved. |
/test all |
@deads2k: The following test failed, say
Full PR test history. Your PR dashboard. Please help us cut down on flakes by linking to an open issue when you hit one in your PR. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here. |
Automatic merge from submit-queue. If you want to cherry-pick this change to another branch, please follow the instructions here. |
xref #29698
xref #38756
xref #49504
xref #38810
Allow
*/subresource
format in RBAC policy rules to support polymorphic subresources like*/scale
for HPA.@DirectXMan12 fyi