Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
33 changes: 33 additions & 0 deletions config/iam/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
# Customer status access

With subresource authorization enabled, customers can access the `/status`
endpoint only for Connectors:

| Role | Connector status access |
| --- | --- |
| Connector Viewer, Network Viewer | Read |
| Connector Admin, Network Admin | Read, update, patch |
| Other networking roles | None |

Network roles inherit these permissions from the corresponding Connector role.
Customers can still read observed status through their existing resource get,
list, and watch permissions. Status endpoints for other resources are reserved
for controllers and separately authorized staff; declaring a subresource does
not grant access to it. Existing Kubernetes controller RBAC is unchanged.

The ProtectedResources declare `get`, `update`, and `patch` for the status
subresources served by our CRDs. HTTPRouteFilters, EndpointSlices, and Leases do
not serve a status subresource and have no status declaration.

## Rollout

This configuration depends on [Milo #824](https://github.com/milo-os/milo/pull/824)
and [openfga-provider #139](https://github.com/milo-os/openfga-provider/pull/139).
Install the updated ProtectedResource schema, apply the subresource declarations,
then enable subresource authorization on the provider manager and wait for its
model to converge. Apply the Connector Role changes and wait for the Roles and
PolicyBindings to become ready before enabling enforcement on the webhook.

The provider feature remains off by default; these manifests do not enable it.
Do not apply the new Connector Role permissions while the manager feature is
off: the manager does not recognize subresource permissions in that mode.
6 changes: 6 additions & 0 deletions config/iam/protected-resources/backends.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,12 @@ spec:
- update
- patch
- delete
subresources:
- name: status
permissions:
- get
- update
- patch
parentResources:
- apiGroup: resourcemanager.miloapis.com
kind: Project
6 changes: 6 additions & 0 deletions config/iam/protected-resources/backendtlspolicies.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,12 @@ spec:
- update
- patch
- delete
subresources:
- name: status
permissions:
- get
- update
- patch
parentResources:
- apiGroup: resourcemanager.miloapis.com
kind: Project
6 changes: 6 additions & 0 deletions config/iam/protected-resources/backendtrafficpolicies.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,12 @@ spec:
- update
- patch
- delete
subresources:
- name: status
permissions:
- get
- update
- patch
parentResources:
- apiGroup: resourcemanager.miloapis.com
kind: Project
6 changes: 6 additions & 0 deletions config/iam/protected-resources/connectoradvertisements.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,12 @@ spec:
- update
- patch
- delete
subresources:
- name: status
permissions:
- get
- update
- patch
parentResources:
- apiGroup: resourcemanager.miloapis.com
kind: Project
6 changes: 6 additions & 0 deletions config/iam/protected-resources/connectorclasses.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,12 @@ spec:
- update
- patch
- delete
subresources:
- name: status
permissions:
- get
- update
- patch
parentResources:
- apiGroup: resourcemanager.miloapis.com
kind: Project
6 changes: 6 additions & 0 deletions config/iam/protected-resources/connectors.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,12 @@ spec:
- update
- patch
- delete
subresources:
- name: status
permissions:
- get
- update
- patch
parentResources:
- apiGroup: resourcemanager.miloapis.com
kind: Project
6 changes: 6 additions & 0 deletions config/iam/protected-resources/domains.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,12 @@ spec:
- update
- patch
- delete
subresources:
- name: status
permissions:
- get
- update
- patch
parentResources:
- apiGroup: resourcemanager.miloapis.com
kind: Project
6 changes: 6 additions & 0 deletions config/iam/protected-resources/gatewayclasses.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,12 @@ spec:
- list
- get
- watch
subresources:
- name: status
permissions:
- get
- update
- patch
parentResources:
- apiGroup: resourcemanager.miloapis.com
kind: Project
6 changes: 6 additions & 0 deletions config/iam/protected-resources/gateways.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,12 @@ spec:
- update
- patch
- delete
subresources:
- name: status
permissions:
- get
- update
- patch
parentResources:
- apiGroup: resourcemanager.miloapis.com
kind: Project
6 changes: 6 additions & 0 deletions config/iam/protected-resources/httpproxies.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,12 @@ spec:
- update
- patch
- delete
subresources:
- name: status
permissions:
- get
- update
- patch
parentResources:
- apiGroup: resourcemanager.miloapis.com
kind: Project
6 changes: 6 additions & 0 deletions config/iam/protected-resources/httproutes.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,12 @@ spec:
- update
- patch
- delete
subresources:
- name: status
permissions:
- get
- update
- patch
parentResources:
- apiGroup: resourcemanager.miloapis.com
kind: Project
6 changes: 6 additions & 0 deletions config/iam/protected-resources/locationbindings.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,12 @@ spec:
- patch
- watch
- delete
subresources:
- name: status
permissions:
- get
- update
- patch
parentResources:
- apiGroup: resourcemanager.miloapis.com
kind: Project
6 changes: 6 additions & 0 deletions config/iam/protected-resources/networkbindings.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,12 @@ spec:
- delete
- patch
- watch
subresources:
- name: status
permissions:
- get
- update
- patch
parentResources:
- apiGroup: networking.datumapis.com
kind: Network
6 changes: 6 additions & 0 deletions config/iam/protected-resources/networkcontexts.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,12 @@ spec:
- delete
- patch
- watch
subresources:
- name: status
permissions:
- get
- update
- patch
parentResources:
- apiGroup: networking.datumapis.com
kind: Network
6 changes: 6 additions & 0 deletions config/iam/protected-resources/networkinterfaceclaims.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,12 @@ spec:
- patch
- watch
- delete
subresources:
- name: status
permissions:
- get
- update
- patch
parentResources:
- apiGroup: resourcemanager.miloapis.com
kind: Project
6 changes: 6 additions & 0 deletions config/iam/protected-resources/networkinterfaces.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,12 @@ spec:
- patch
- watch
- delete
subresources:
- name: status
permissions:
- get
- update
- patch
parentResources:
- apiGroup: resourcemanager.miloapis.com
kind: Project
6 changes: 6 additions & 0 deletions config/iam/protected-resources/networkpolicies.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,12 @@ spec:
- patch
- watch
- delete
subresources:
- name: status
permissions:
- get
- update
- patch
parentResources:
- apiGroup: resourcemanager.miloapis.com
kind: Project
6 changes: 6 additions & 0 deletions config/iam/protected-resources/networks.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,12 @@ spec:
- patch
- watch
- use
subresources:
- name: status
permissions:
- get
- update
- patch
parentResources:
- apiGroup: resourcemanager.miloapis.com
kind: Project
6 changes: 6 additions & 0 deletions config/iam/protected-resources/networkservices.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,12 @@ spec:
- patch
- watch
- delete
subresources:
- name: status
permissions:
- get
- update
- patch
parentResources:
- apiGroup: resourcemanager.miloapis.com
kind: Project
6 changes: 6 additions & 0 deletions config/iam/protected-resources/securitypolicies.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,12 @@ spec:
- update
- patch
- delete
subresources:
- name: status
permissions:
- get
- update
- patch
parentResources:
- apiGroup: resourcemanager.miloapis.com
kind: Project
6 changes: 6 additions & 0 deletions config/iam/protected-resources/subnetclaims.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,12 @@ spec:
- patch
- watch
- delete
subresources:
- name: status
permissions:
- get
- update
- patch
parentResources:
- apiGroup: networking.datumapis.com
kind: NetworkContext
6 changes: 6 additions & 0 deletions config/iam/protected-resources/subnets.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,12 @@ spec:
- patch
- watch
- delete
subresources:
- name: status
permissions:
- get
- update
- patch
parentResources:
- apiGroup: networking.datumapis.com
kind: NetworkContext
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,12 @@ spec:
- update
- patch
- delete
subresources:
- name: status
permissions:
- get
- update
- patch
parentResources:
- apiGroup: resourcemanager.miloapis.com
kind: Project
2 changes: 2 additions & 0 deletions config/iam/roles/connector-admin.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,8 @@ spec:
- networking.datumapis.com/connectors.create
- networking.datumapis.com/connectors.update
- networking.datumapis.com/connectors.patch
- networking.datumapis.com/connectors/status.update
- networking.datumapis.com/connectors/status.patch
- networking.datumapis.com/connectors.delete
- networking.datumapis.com/connectoradvertisements.create
- networking.datumapis.com/connectoradvertisements.update
Expand Down
1 change: 1 addition & 0 deletions config/iam/roles/connector-viewer.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ spec:
includedPermissions:
- networking.datumapis.com/connectors.list
- networking.datumapis.com/connectors.get
- networking.datumapis.com/connectors/status.get
- networking.datumapis.com/connectors.watch
- networking.datumapis.com/connectoradvertisements.list
- networking.datumapis.com/connectoradvertisements.get
Expand Down
Loading