Skip to content

[v1.7] Cherry-pick authentication review rbac rule#628

Closed
rene-dekker wants to merge 1 commit into
tigera:release-v1.7from
rene-dekker:v1.7-cherry-pick-auth-review
Closed

[v1.7] Cherry-pick authentication review rbac rule#628
rene-dekker wants to merge 1 commit into
tigera:release-v1.7from
rene-dekker:v1.7-cherry-pick-auth-review

Conversation

@rene-dekker
Copy link
Copy Markdown
Member

Cherry-pick authentication review rbac rule.
#597

Add clusterrole additions for authenticationreviews such that ui users can be authenticated by es-proxy and compliance.

AuthenticationReviews is a new api in the tigera-apiserver that exchanges the auth header for userinfo. This works for basic, token, oidc and it built to circumvent a bug that is present in k8s versions lower than 1,18 when the oidc audiences flag is used, see kubernetes/kubernetes#87612

[master] Add clusterrole for authenticationreviews
@rene-dekker rene-dekker changed the title Cherry-pick authentication review rbac rule [v1.7] Cherry-pick authentication review rbac rule Jun 16, 2020
@rene-dekker
Copy link
Copy Markdown
Member Author

Closed at it is not very likely at this time that the authentication reviews functionality will be merged to this release.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants