Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

✨ auth: use synthetic user/group when service account is not defined #1816

Draft
wants to merge 2 commits into
base: main
Choose a base branch
from

Conversation

joelanford
Copy link
Member

Description

Today at a meeting among maintainers of OLMv1, we discussed an idea that @thetechnick proposed awhile back. That is: stop using service accounts and service account tokens. Instead use synthetic names with impersonation.

While we are now 1.0.0 with support for service accounts, we can deprecate that feature and recommend attaching permissions to synthetic users/groups instead.

This PR demonstrates how we might do this. But with the API change, we should write up a detailed design and gain consensus.

This PR uses:

  • User: "olmv1:clusterextensions:<clusterExtensionName>:admin"
  • Groups: ["system:authenticated", "olmv1:clusterextensions:admin"]

But I'm not sure this is the best setup. There's more discussion to be had around what sythentic names/groups we could derive from a cluster extension.

Reviewer Checklist

  • API Go Documentation
  • Tests: Unit Tests (and E2E Tests, if appropriate)
  • Comprehensive Commit Messages
  • Links to related GitHub Issue(s)

@openshift-ci openshift-ci bot added the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Feb 26, 2025
Copy link

netlify bot commented Feb 26, 2025

Deploy Preview for olmv1 ready!

Name Link
🔨 Latest commit e44c4d2
🔍 Latest deploy log https://app.netlify.com/sites/olmv1/deploys/67bff2da237a170008ffc1b3
😎 Deploy Preview https://deploy-preview-1816--olmv1.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site configuration.

@joelanford joelanford force-pushed the synthetic-permissions branch 3 times, most recently from dfc5ccb to fbcc4a5 Compare February 26, 2025 22:35
Copy link

codecov bot commented Feb 26, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 68.64%. Comparing base (1573846) to head (e44c4d2).

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #1816      +/-   ##
==========================================
+ Coverage   68.39%   68.64%   +0.24%     
==========================================
  Files          62       63       +1     
  Lines        5117     5151      +34     
==========================================
+ Hits         3500     3536      +36     
+ Misses       1388     1387       -1     
+ Partials      229      228       -1     
Flag Coverage Δ
e2e 52.28% <100.00%> (+0.49%) ⬆️
unit 55.52% <0.00%> (-0.39%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@joelanford joelanford force-pushed the synthetic-permissions branch from fbcc4a5 to e0c2a55 Compare February 26, 2025 23:40
Signed-off-by: Joe Lanford <[email protected]>
@joelanford joelanford force-pushed the synthetic-permissions branch from e0c2a55 to 11210fc Compare February 27, 2025 03:21
@joelanford joelanford force-pushed the synthetic-permissions branch from 11210fc to e44c4d2 Compare February 27, 2025 05:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant