-
Incorporate mahy-group-chat and ralston-policy documents, deduplicate ideas.
-
Problem:
The `resourceNames` property in RBAC Role and ClusterRole is limited in usefulness because it is not currently possible to scope dynamically to pods created by a `Deployment`, `Daemonset`, `…
-
For now all secrets are being spreaded all over namespace and in final cluster as well. We should avoid having secrets accessible by other pods than we want. That means we need to prepare RBACs and mo…
-
Currently the Helm chart provides more cluster wide permissions against the k8s api-server than may be needed, depending on configuration of dask-gateway.
The following PRs are opened related to th…
-
Hey,
Hope you are doing well.
## Description
As a company, we would like to manage RBAC in buildkite (and everywhere else) as IaC using terraform. We are currently missing the possibility to …
-
Is it possible for you to implement a simple dynamic RBAC system? Thanks
-
### Problem Statement
RBAC permissions are still unnecessarily wide today in that `pods` and `pod/exec` are granted too broadly. This isn't necessary as the only Pod which needs to be created and exe…
-
Not sure if this is possible, but we use private repos and I sort of need to create a subschema. Is it possible to add the ability to call a relative path using $ref?
alternatively, is there any wa…
-
**What kind of request is this (question/bug/enhancement/feature request):** bug
**Steps to reproduce (least amount of steps as possible):**
1. Create a cluster with Azure cloud provider set. (1…
-
## Proposal
This proposal is to discuss the addition of dynamic Namespace discovery for Traefik in Kubernetes.
### Background
Currently, it is possible to configure the Namespaces watched by …