Skip to content

[v1.3] Cherry-pick authentication review rbac rule#633

Merged
tmjd merged 1 commit into
tigera:release-v1.3from
rene-dekker:v1.3-cherry-pick-auth-review
Jun 23, 2020
Merged

[v1.3] Cherry-pick authentication review rbac rule#633
tmjd merged 1 commit into
tigera:release-v1.3from
rene-dekker:v1.3-cherry-pick-auth-review

Conversation

@rene-dekker
Copy link
Copy Markdown
Member

Cherry-pick authentication review rbac rule.
#597

Add clusterrole additions for authenticationreviews such that ui users can be authenticated by es-proxy and compliance.

AuthenticationReviews is a new api in the tigera-apiserver that exchanges the auth header for userinfo. This works for basic, token, oidc and it built to circumvent a bug that is present in k8s versions lower than 1,18 when the oidc audiences flag is used, see kubernetes/kubernetes#87612

[master] Add clusterrole for authenticationreviews
@tmjd tmjd merged commit e199354 into tigera:release-v1.3 Jun 23, 2020
@tmjd tmjd added the enterprise Feature applies to enterprise only label Jun 23, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enterprise Feature applies to enterprise only

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants