Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Restrict clusterroles used by Pixie operator #1984

Open
aimichelle opened this issue Aug 16, 2024 · 0 comments
Open

Restrict clusterroles used by Pixie operator #1984

aimichelle opened this issue Aug 16, 2024 · 0 comments

Comments

@aimichelle
Copy link
Member

Describe the bug
Installing the Pixie operator currently deploys a clusterrole which allows the operator to create other clusterroles when deploying Vizier. This is because Vizier itself requires a clusterrole to allow it to list nodes/namespaces.
It is better to restrict the operator's clusterrole permissions, as this can be used to create more permissive clusterroles.

Expected behavior
Having the Vizier clusterrole to list nodes/namespaces is still a requirement in Pixie. However, we should investigate updating the operator so that it deploys with those clusterroles off-the-bat, rather than having the ability to create new clusterroles.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant