Skip to content

[v1.4] Cherry-pick authentication review rbac rule#631

Closed
rene-dekker wants to merge 1 commit into
tigera:release-v1.4from
rene-dekker:v1.4-cherry-pick-auth-review
Closed

[v1.4] Cherry-pick authentication review rbac rule#631
rene-dekker wants to merge 1 commit into
tigera:release-v1.4from
rene-dekker:v1.4-cherry-pick-auth-review

Conversation

@rene-dekker
Copy link
Copy Markdown
Member

Cherry-pick authentication review rbac rule.
#597

Add clusterrole additions for authenticationreviews such that ui users can be authenticated by es-proxy and compliance.

AuthenticationReviews is a new api in the tigera-apiserver that exchanges the auth header for userinfo. This works for basic, token, oidc and it built to circumvent a bug that is present in k8s versions lower than 1,18 when the oidc audiences flag is used, see kubernetes/kubernetes#87612

[master] Add clusterrole for authenticationreviews
@rene-dekker rene-dekker changed the base branch from master to release-v1.4 June 16, 2020 18:13
@CLAassistant
Copy link
Copy Markdown

CLAassistant commented Jun 16, 2020

CLA assistant check
All committers have signed the CLA.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants