diff --git a/config/iam/README.md b/config/iam/README.md new file mode 100644 index 00000000..e11e34ad --- /dev/null +++ b/config/iam/README.md @@ -0,0 +1,33 @@ +# Customer status access + +With subresource authorization enabled, customers can access the `/status` +endpoint only for Connectors: + +| Role | Connector status access | +| --- | --- | +| Connector Viewer, Network Viewer | Read | +| Connector Admin, Network Admin | Read, update, patch | +| Other networking roles | None | + +Network roles inherit these permissions from the corresponding Connector role. +Customers can still read observed status through their existing resource get, +list, and watch permissions. Status endpoints for other resources are reserved +for controllers and separately authorized staff; declaring a subresource does +not grant access to it. Existing Kubernetes controller RBAC is unchanged. + +The ProtectedResources declare `get`, `update`, and `patch` for the status +subresources served by our CRDs. HTTPRouteFilters, EndpointSlices, and Leases do +not serve a status subresource and have no status declaration. + +## Rollout + +This configuration depends on [Milo #824](https://github.com/milo-os/milo/pull/824) +and [openfga-provider #139](https://github.com/milo-os/openfga-provider/pull/139). +Install the updated ProtectedResource schema, apply the subresource declarations, +then enable subresource authorization on the provider manager and wait for its +model to converge. Apply the Connector Role changes and wait for the Roles and +PolicyBindings to become ready before enabling enforcement on the webhook. + +The provider feature remains off by default; these manifests do not enable it. +Do not apply the new Connector Role permissions while the manager feature is +off: the manager does not recognize subresource permissions in that mode. diff --git a/config/iam/protected-resources/backends.yaml b/config/iam/protected-resources/backends.yaml index 81f2914b..afb5a472 100644 --- a/config/iam/protected-resources/backends.yaml +++ b/config/iam/protected-resources/backends.yaml @@ -17,6 +17,12 @@ spec: - update - patch - delete + subresources: + - name: status + permissions: + - get + - update + - patch parentResources: - apiGroup: resourcemanager.miloapis.com kind: Project diff --git a/config/iam/protected-resources/backendtlspolicies.yaml b/config/iam/protected-resources/backendtlspolicies.yaml index fd0cef90..17703dbe 100644 --- a/config/iam/protected-resources/backendtlspolicies.yaml +++ b/config/iam/protected-resources/backendtlspolicies.yaml @@ -17,6 +17,12 @@ spec: - update - patch - delete + subresources: + - name: status + permissions: + - get + - update + - patch parentResources: - apiGroup: resourcemanager.miloapis.com kind: Project diff --git a/config/iam/protected-resources/backendtrafficpolicies.yaml b/config/iam/protected-resources/backendtrafficpolicies.yaml index f6ebfb44..6e9ba75e 100644 --- a/config/iam/protected-resources/backendtrafficpolicies.yaml +++ b/config/iam/protected-resources/backendtrafficpolicies.yaml @@ -17,6 +17,12 @@ spec: - update - patch - delete + subresources: + - name: status + permissions: + - get + - update + - patch parentResources: - apiGroup: resourcemanager.miloapis.com kind: Project diff --git a/config/iam/protected-resources/connectoradvertisements.yaml b/config/iam/protected-resources/connectoradvertisements.yaml index 8b182486..c4d43ad0 100644 --- a/config/iam/protected-resources/connectoradvertisements.yaml +++ b/config/iam/protected-resources/connectoradvertisements.yaml @@ -17,6 +17,12 @@ spec: - update - patch - delete + subresources: + - name: status + permissions: + - get + - update + - patch parentResources: - apiGroup: resourcemanager.miloapis.com kind: Project diff --git a/config/iam/protected-resources/connectorclasses.yaml b/config/iam/protected-resources/connectorclasses.yaml index 3c8298df..b8ef100b 100644 --- a/config/iam/protected-resources/connectorclasses.yaml +++ b/config/iam/protected-resources/connectorclasses.yaml @@ -17,6 +17,12 @@ spec: - update - patch - delete + subresources: + - name: status + permissions: + - get + - update + - patch parentResources: - apiGroup: resourcemanager.miloapis.com kind: Project diff --git a/config/iam/protected-resources/connectors.yaml b/config/iam/protected-resources/connectors.yaml index 4b26fb33..9a9a5d60 100644 --- a/config/iam/protected-resources/connectors.yaml +++ b/config/iam/protected-resources/connectors.yaml @@ -17,6 +17,12 @@ spec: - update - patch - delete + subresources: + - name: status + permissions: + - get + - update + - patch parentResources: - apiGroup: resourcemanager.miloapis.com kind: Project diff --git a/config/iam/protected-resources/domains.yaml b/config/iam/protected-resources/domains.yaml index 0d9fb980..bdfadcfe 100644 --- a/config/iam/protected-resources/domains.yaml +++ b/config/iam/protected-resources/domains.yaml @@ -17,6 +17,12 @@ spec: - update - patch - delete + subresources: + - name: status + permissions: + - get + - update + - patch parentResources: - apiGroup: resourcemanager.miloapis.com kind: Project diff --git a/config/iam/protected-resources/gatewayclasses.yaml b/config/iam/protected-resources/gatewayclasses.yaml index 5297c881..295e8cd0 100644 --- a/config/iam/protected-resources/gatewayclasses.yaml +++ b/config/iam/protected-resources/gatewayclasses.yaml @@ -13,6 +13,12 @@ spec: - list - get - watch + subresources: + - name: status + permissions: + - get + - update + - patch parentResources: - apiGroup: resourcemanager.miloapis.com kind: Project diff --git a/config/iam/protected-resources/gateways.yaml b/config/iam/protected-resources/gateways.yaml index 1e90a50b..1c93937e 100644 --- a/config/iam/protected-resources/gateways.yaml +++ b/config/iam/protected-resources/gateways.yaml @@ -17,6 +17,12 @@ spec: - update - patch - delete + subresources: + - name: status + permissions: + - get + - update + - patch parentResources: - apiGroup: resourcemanager.miloapis.com kind: Project diff --git a/config/iam/protected-resources/httpproxies.yaml b/config/iam/protected-resources/httpproxies.yaml index ace9e6a2..c4d517fb 100644 --- a/config/iam/protected-resources/httpproxies.yaml +++ b/config/iam/protected-resources/httpproxies.yaml @@ -17,6 +17,12 @@ spec: - update - patch - delete + subresources: + - name: status + permissions: + - get + - update + - patch parentResources: - apiGroup: resourcemanager.miloapis.com kind: Project diff --git a/config/iam/protected-resources/httproutes.yaml b/config/iam/protected-resources/httproutes.yaml index 1946c665..4e97411b 100644 --- a/config/iam/protected-resources/httproutes.yaml +++ b/config/iam/protected-resources/httproutes.yaml @@ -17,6 +17,12 @@ spec: - update - patch - delete + subresources: + - name: status + permissions: + - get + - update + - patch parentResources: - apiGroup: resourcemanager.miloapis.com kind: Project diff --git a/config/iam/protected-resources/locationbindings.yaml b/config/iam/protected-resources/locationbindings.yaml index 116ea173..555a0dc7 100644 --- a/config/iam/protected-resources/locationbindings.yaml +++ b/config/iam/protected-resources/locationbindings.yaml @@ -16,6 +16,12 @@ spec: - patch - watch - delete + subresources: + - name: status + permissions: + - get + - update + - patch parentResources: - apiGroup: resourcemanager.miloapis.com kind: Project diff --git a/config/iam/protected-resources/networkbindings.yaml b/config/iam/protected-resources/networkbindings.yaml index 74c8e27d..a4df8f39 100644 --- a/config/iam/protected-resources/networkbindings.yaml +++ b/config/iam/protected-resources/networkbindings.yaml @@ -16,6 +16,12 @@ spec: - delete - patch - watch + subresources: + - name: status + permissions: + - get + - update + - patch parentResources: - apiGroup: networking.datumapis.com kind: Network diff --git a/config/iam/protected-resources/networkcontexts.yaml b/config/iam/protected-resources/networkcontexts.yaml index a5882657..e8c968f7 100644 --- a/config/iam/protected-resources/networkcontexts.yaml +++ b/config/iam/protected-resources/networkcontexts.yaml @@ -16,6 +16,12 @@ spec: - delete - patch - watch + subresources: + - name: status + permissions: + - get + - update + - patch parentResources: - apiGroup: networking.datumapis.com kind: Network diff --git a/config/iam/protected-resources/networkinterfaceclaims.yaml b/config/iam/protected-resources/networkinterfaceclaims.yaml index 2ec2c212..47bb4a87 100644 --- a/config/iam/protected-resources/networkinterfaceclaims.yaml +++ b/config/iam/protected-resources/networkinterfaceclaims.yaml @@ -16,6 +16,12 @@ spec: - patch - watch - delete + subresources: + - name: status + permissions: + - get + - update + - patch parentResources: - apiGroup: resourcemanager.miloapis.com kind: Project diff --git a/config/iam/protected-resources/networkinterfaces.yaml b/config/iam/protected-resources/networkinterfaces.yaml index 47c9ea1f..feadbe22 100644 --- a/config/iam/protected-resources/networkinterfaces.yaml +++ b/config/iam/protected-resources/networkinterfaces.yaml @@ -16,6 +16,12 @@ spec: - patch - watch - delete + subresources: + - name: status + permissions: + - get + - update + - patch parentResources: - apiGroup: resourcemanager.miloapis.com kind: Project diff --git a/config/iam/protected-resources/networkpolicies.yaml b/config/iam/protected-resources/networkpolicies.yaml index cd3f1c87..d2603eeb 100644 --- a/config/iam/protected-resources/networkpolicies.yaml +++ b/config/iam/protected-resources/networkpolicies.yaml @@ -16,6 +16,12 @@ spec: - patch - watch - delete + subresources: + - name: status + permissions: + - get + - update + - patch parentResources: - apiGroup: resourcemanager.miloapis.com kind: Project diff --git a/config/iam/protected-resources/networks.yaml b/config/iam/protected-resources/networks.yaml index 78d58083..9d25c895 100644 --- a/config/iam/protected-resources/networks.yaml +++ b/config/iam/protected-resources/networks.yaml @@ -18,6 +18,12 @@ spec: - patch - watch - use + subresources: + - name: status + permissions: + - get + - update + - patch parentResources: - apiGroup: resourcemanager.miloapis.com kind: Project diff --git a/config/iam/protected-resources/networkservices.yaml b/config/iam/protected-resources/networkservices.yaml index aca99332..63b76c5f 100644 --- a/config/iam/protected-resources/networkservices.yaml +++ b/config/iam/protected-resources/networkservices.yaml @@ -16,6 +16,12 @@ spec: - patch - watch - delete + subresources: + - name: status + permissions: + - get + - update + - patch parentResources: - apiGroup: resourcemanager.miloapis.com kind: Project diff --git a/config/iam/protected-resources/securitypolicies.yaml b/config/iam/protected-resources/securitypolicies.yaml index 7610f99f..13629dae 100644 --- a/config/iam/protected-resources/securitypolicies.yaml +++ b/config/iam/protected-resources/securitypolicies.yaml @@ -17,6 +17,12 @@ spec: - update - patch - delete + subresources: + - name: status + permissions: + - get + - update + - patch parentResources: - apiGroup: resourcemanager.miloapis.com kind: Project diff --git a/config/iam/protected-resources/subnetclaims.yaml b/config/iam/protected-resources/subnetclaims.yaml index dde7288d..9c77e99f 100644 --- a/config/iam/protected-resources/subnetclaims.yaml +++ b/config/iam/protected-resources/subnetclaims.yaml @@ -16,6 +16,12 @@ spec: - patch - watch - delete + subresources: + - name: status + permissions: + - get + - update + - patch parentResources: - apiGroup: networking.datumapis.com kind: NetworkContext diff --git a/config/iam/protected-resources/subnets.yaml b/config/iam/protected-resources/subnets.yaml index 1796e1bd..6901729b 100644 --- a/config/iam/protected-resources/subnets.yaml +++ b/config/iam/protected-resources/subnets.yaml @@ -16,6 +16,12 @@ spec: - patch - watch - delete + subresources: + - name: status + permissions: + - get + - update + - patch parentResources: - apiGroup: networking.datumapis.com kind: NetworkContext diff --git a/config/iam/protected-resources/trafficprotectionpolicies.yaml b/config/iam/protected-resources/trafficprotectionpolicies.yaml index ab053106..64668409 100644 --- a/config/iam/protected-resources/trafficprotectionpolicies.yaml +++ b/config/iam/protected-resources/trafficprotectionpolicies.yaml @@ -17,6 +17,12 @@ spec: - update - patch - delete + subresources: + - name: status + permissions: + - get + - update + - patch parentResources: - apiGroup: resourcemanager.miloapis.com kind: Project diff --git a/config/iam/roles/connector-admin.yaml b/config/iam/roles/connector-admin.yaml index 0f1c5eb1..aae40937 100644 --- a/config/iam/roles/connector-admin.yaml +++ b/config/iam/roles/connector-admin.yaml @@ -13,6 +13,8 @@ spec: - networking.datumapis.com/connectors.create - networking.datumapis.com/connectors.update - networking.datumapis.com/connectors.patch + - networking.datumapis.com/connectors/status.update + - networking.datumapis.com/connectors/status.patch - networking.datumapis.com/connectors.delete - networking.datumapis.com/connectoradvertisements.create - networking.datumapis.com/connectoradvertisements.update diff --git a/config/iam/roles/connector-viewer.yaml b/config/iam/roles/connector-viewer.yaml index 61080466..ae3d9304 100644 --- a/config/iam/roles/connector-viewer.yaml +++ b/config/iam/roles/connector-viewer.yaml @@ -10,6 +10,7 @@ spec: includedPermissions: - networking.datumapis.com/connectors.list - networking.datumapis.com/connectors.get + - networking.datumapis.com/connectors/status.get - networking.datumapis.com/connectors.watch - networking.datumapis.com/connectoradvertisements.list - networking.datumapis.com/connectoradvertisements.get