jayunit100 / network-policy-subproject

A starter repo to donate to Kubernetes-sigs so the community can own and iterate on stories over time, with issue tracking, as we close out the policy++ wg
13 stars 12 forks source link

Verify if labels can be forbidden via RBAC on namespaces #15

Closed jayunit100 closed 3 years ago

jayunit100 commented 4 years ago

(assumption = no)

jayunit100 commented 4 years ago

modulo something like an admission controller (https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-isolation-restriction) this isn't something that seems like it can be done, since RBAC is done at object level.

jayunit100 commented 4 years ago

I think we can close this, but @cmluciano can decide...

jayunit100 commented 3 years ago

am assuming Chris your ok with this conclusion