Skip to content

Commit

Permalink
Merge pull request #1303 from sanchezl/apirequestcount-skip-audit
Browse files Browse the repository at this point in the history
Bug 2049687: superfluous apirequestcount entries in audit log
  • Loading branch information
openshift-merge-robot committed Feb 3, 2022
2 parents 2a46ecd + 0a143d8 commit 45e0cde
Show file tree
Hide file tree
Showing 8 changed files with 56 additions and 0 deletions.
7 changes: 7 additions & 0 deletions pkg/operator/apiserver/audit/bindata/bindata.go

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

7 changes: 7 additions & 0 deletions pkg/operator/apiserver/audit/manifests/base-policy.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -19,3 +19,10 @@
- "/version"
- "/healthz"
- "/readyz"
# Don't log requests by "system:apiserver" on apirequestcounts
- level: None
users: ["system:apiserver"]
resources:
- group: "apiserver.openshift.io"
resources: ["apirequestcounts", "apirequestcounts/*"]
namespaces: [""]
7 changes: 7 additions & 0 deletions pkg/operator/apiserver/audit/testdata/allrequestbodies.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,13 @@ rules:
- "/version"
- "/healthz"
- "/readyz"
# Don't log requests by "system:apiserver" on apirequestcounts
- level: None
users: ["system:apiserver"]
resources:
- group: "apiserver.openshift.io"
resources: ["apirequestcounts", "apirequestcounts/*"]
namespaces: [""]
# exclude resources where the body is security-sensitive
- level: Metadata
resources:
Expand Down
7 changes: 7 additions & 0 deletions pkg/operator/apiserver/audit/testdata/default.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,13 @@
- "/version"
- "/healthz"
- "/readyz"
# Don't log requests by "system:apiserver" on apirequestcounts
- level: None
users: ["system:apiserver"]
resources:
- group: "apiserver.openshift.io"
resources: ["apirequestcounts", "apirequestcounts/*"]
namespaces: [""]
# Log the full Identity API resource object so that the audit trail
# allows us to match the username with the IDP identity.
- level: RequestResponse
Expand Down
7 changes: 7 additions & 0 deletions pkg/operator/apiserver/audit/testdata/multipleCr.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,13 @@ rules:
- "/version"
- "/healthz"
- "/readyz"
# Don't log requests by "system:apiserver" on apirequestcounts
- level: None
users: ["system:apiserver"]
resources:
- group: "apiserver.openshift.io"
resources: ["apirequestcounts", "apirequestcounts/*"]
namespaces: [""]
# exclude resources where the body is security-sensitive
- level: Metadata
resources:
Expand Down
7 changes: 7 additions & 0 deletions pkg/operator/apiserver/audit/testdata/none.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -21,4 +21,11 @@ rules:
- "/version"
- "/healthz"
- "/readyz"
# Don't log requests by "system:apiserver" on apirequestcounts
- level: None
users: ["system:apiserver"]
resources:
- group: "apiserver.openshift.io"
resources: ["apirequestcounts", "apirequestcounts/*"]
namespaces: [""]
- level: None
7 changes: 7 additions & 0 deletions pkg/operator/apiserver/audit/testdata/oauth.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,13 @@ rules:
- "/version"
- "/healthz"
- "/readyz"
# Don't log requests by "system:apiserver" on apirequestcounts
- level: None
users: ["system:apiserver"]
resources:
- group: "apiserver.openshift.io"
resources: ["apirequestcounts", "apirequestcounts/*"]
namespaces: [""]
# exclude resources where the body is security-sensitive
- level: Metadata
resources:
Expand Down
7 changes: 7 additions & 0 deletions pkg/operator/apiserver/audit/testdata/writerequestbodies.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,13 @@ rules:
- "/version"
- "/healthz"
- "/readyz"
# Don't log requests by "system:apiserver" on apirequestcounts
- level: None
users: ["system:apiserver"]
resources:
- group: "apiserver.openshift.io"
resources: ["apirequestcounts", "apirequestcounts/*"]
namespaces: [""]
# exclude resources where the body is security-sensitive
- level: Metadata
resources:
Expand Down

0 comments on commit 45e0cde

Please sign in to comment.