Skip to content

[master] Add clusterrole for authenticationreviews#597

Merged
tmjd merged 1 commit into
tigera:masterfrom
rene-dekker:mstr-saas-871
Jun 15, 2020
Merged

[master] Add clusterrole for authenticationreviews#597
tmjd merged 1 commit into
tigera:masterfrom
rene-dekker:mstr-saas-871

Conversation

@rene-dekker
Copy link
Copy Markdown
Member

Add clusterrole additions for authenticationreviews such that ui users can be authenticated by es-proxy and compliance.

AuthenticationReviews is a new api in the tigera-apiserver that exchanges the auth header for userinfo. This works for basic, token, oidc and it built to circumvent a bug that is present in k8s versions lower than 1,18 when the oidc audiences flag is used, see kubernetes/kubernetes#87612

@rene-dekker rene-dekker changed the title Add clusterrole for authenticationreviews such that UI users can be a… [master] Add clusterrole for authenticationreviews May 29, 2020
@tmjd tmjd added this to the 1.8.0 milestone Jun 13, 2020
@tmjd tmjd added enterprise Feature applies to enterprise only kind/bug Something isn't working and removed kind/bug Something isn't working labels Jun 13, 2020
Copy link
Copy Markdown
Member

@tmjd tmjd left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@tmjd
Copy link
Copy Markdown
Member

tmjd commented Jun 15, 2020

v2.7 was updated with #595

@tmjd tmjd merged commit a1de0ff into tigera:master Jun 15, 2020
@rene-dekker rene-dekker deleted the mstr-saas-871 branch June 15, 2020 22:26
rene-dekker pushed a commit to rene-dekker/operator that referenced this pull request Jun 16, 2020
[master] Add clusterrole for authenticationreviews
rene-dekker pushed a commit to rene-dekker/operator that referenced this pull request Jun 16, 2020
[master] Add clusterrole for authenticationreviews
rene-dekker pushed a commit to rene-dekker/operator that referenced this pull request Jun 16, 2020
[master] Add clusterrole for authenticationreviews
rene-dekker pushed a commit to rene-dekker/operator that referenced this pull request Jun 16, 2020
[master] Add clusterrole for authenticationreviews
rene-dekker pushed a commit to rene-dekker/operator that referenced this pull request Jun 16, 2020
[master] Add clusterrole for authenticationreviews
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enterprise Feature applies to enterprise only

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants