kcp-dev / contrib-tmc

An experimental add-on readding some Kubernetes compute APIs and impement transparent multi-cluster scheduling
Apache License 2.0
5 stars 3 forks source link

Syncer uses minimal permissions in workload cluster #139

Open pweil- opened 2 years ago

pweil- commented 2 years ago

Proposal: webhook admission controller to ensure only syncer is creating namespaces with the configured prefix Proposal: RBAC controller to grant syncer full access to namespaces with the configured prefix Proposal: installing both of the above when we install syncer, health-checking them when determining cluster readiness

mjudeikis commented 9 months ago

/transfer-issue contrib-tmc