Skip to content

Grant calico-manager broad read access to UISettings resources#4701

Merged
caseydavenport merged 1 commit intotigera:release-v1.42from
caseydavenport:casey-uisettings-rbac
Apr 16, 2026
Merged

Grant calico-manager broad read access to UISettings resources#4701
caseydavenport merged 1 commit intotigera:release-v1.42from
caseydavenport:casey-uisettings-rbac

Conversation

@caseydavenport
Copy link
Copy Markdown
Member

Cherry-pick of #4676 to release-v1.42.

ui-apis now serves UISettings reads on behalf of users via Voltron. The calico-manager SA needs get/list/watch on uisettings, uisettingsgroups, and uisettingsgroups/data to fetch resources before performing SubjectAccessReviews to enforce per-group RBAC.

None

…a#4676)

ui-apis now serves UISettings reads on behalf of users via Voltron. It needs
get/list/watch on uisettings, uisettingsgroups, and uisettingsgroups/data to
fetch resources, then performs SubjectAccessReviews to enforce per-group RBAC
before returning results.
@caseydavenport caseydavenport force-pushed the casey-uisettings-rbac branch from 8969488 to 71a2d20 Compare April 16, 2026 04:37
@caseydavenport caseydavenport merged commit 03d2873 into tigera:release-v1.42 Apr 16, 2026
2 of 3 checks passed
@caseydavenport caseydavenport deleted the casey-uisettings-rbac branch April 16, 2026 04:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants