gardener / gardener-extension-provider-azure

Gardener extension controller for the Azure cloud provider (https://azure.microsoft.com).
https://gardener.cloud
Apache License 2.0
10 stars 81 forks source link

[GEP-26] CredentialsBinding validation via admission webhook #957

Closed dimityrmirchev closed 2 months ago

dimityrmirchev commented 2 months ago

How to categorize this PR?

/area security ipcei /kind enhancement /label ipcei/workload-identity /platform azure

What this PR does / why we need it:

Which issue(s) this PR fixes: Part of https://github.com/gardener/gardener/issues/9586

Special notes for your reviewer: cc @vpnachev

Release note:

The admission webhook now validates `CredentialsBinding`s.
gardener-robot commented 2 months ago

@dimityrmirchev Label ipcei/workload-identity does not exist.

dimityrmirchev commented 2 months ago

Converting to draft until https://github.com/gardener/gardener-extension-provider-aws/pull/1047 is finalized.