You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We have opened a proposal to drastically reduce the Kubernetes RBAC grants a telepresence client needs — down to a single name-scoped pods/portforward rule, or no Kubernetes API access at all when an admin publishes an external traffic-manager endpoint. The traffic-manager already authenticates every caller and authorizes operations against the verified identity, so it can take over the namespace watching, log fetching, and discovery the client does today.
The full proposal, including how authorization works once the port-forward is no longer the gate, is in issue #4264.
Feedback is very welcome — either here or on the issue.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
We have opened a proposal to drastically reduce the Kubernetes RBAC grants a telepresence client needs — down to a single name-scoped
pods/portforwardrule, or no Kubernetes API access at all when an admin publishes an external traffic-manager endpoint. The traffic-manager already authenticates every caller and authorizes operations against the verified identity, so it can take over the namespace watching, log fetching, and discovery the client does today.The full proposal, including how authorization works once the port-forward is no longer the gate, is in issue #4264.
Feedback is very welcome — either here or on the issue.
All reactions