-
-
Notifications
You must be signed in to change notification settings - Fork 7
Grant the privileges required for graceful shutdowns to the admin user in the OPA rego rules #575
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The idea and change LGTM. However, I would prefer if we don't slam just every permission on the admin
user, but would only add the need permissions, rw
on system_information
in this case. I know this might make the rules a bit more complicated...
I would be even happier if we would use meanifung names, so not admin but graceful-shutdown
for graceful shutdown. But I need to check what happens on TrinoClusters without OPA (will they get a 403?)
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Many thanks
FYI, I'm copying the new rule to the end-to-end-security demo. I hope they will not be changed before merging |
Description
Grant the privileges required for graceful shutdowns to the admin user in the OPA rego rules
Required for #574
Definition of Done Checklist