Closed pschisa closed 2 weeks ago
kubernetes_resources:
- kind: '*'
name: '*'
namespace: teleport
verbs:
- '*'
This config allows accessing all kinds inside the namespace teleport
. To allow access to the namespace itself (and everything inside of it by extension) we need to use kind: namespace
, so config will look like this:
kubernetes_resources:
- kind: namespace
name: teleport
verbs:
- '*'
thanks @AntonAM that worked! I made a quick PR to update the docs
Expected behavior: When attempting to follow the documentation for cluster scoped resource access requests to a specific namespace, having the following RBAC permissions in the search as role will provide access to the indicated namespace (in the example,
teleport
):Current behavior: When attempting to create an access request for a specific namespace, it only succeeds if a wildcard is used in the RBAC permissions.
This means users who wish to request a namespace via resource access requests must either have permission to request any namespace or the must resort to role-based access requets
Bug details:
Failing attempt with scoped namespace:
working attempt after changing to wildcard