Coder Social home page Coder Social logo

Enhancement of Authentication and Authorization Filters to Allow Custom Configurations and Stability Improvements about controller-runtime HOT 8 OPEN

camilamacedo86 avatar camilamacedo86 commented on September 21, 2024
Enhancement of Authentication and Authorization Filters to Allow Custom Configurations and Stability Improvements

from controller-runtime.

Comments (8)

sbueringer avatar sbueringer commented on September 21, 2024 3

We don't even have a /healthz endpoint on the metrics server. But I get the point for metrics

from controller-runtime.

sbueringer avatar sbueringer commented on September 21, 2024 2

/lifecycle frozen

from controller-runtime.

camilamacedo86 avatar camilamacedo86 commented on September 21, 2024

HI @deads2k,

First of all, thank you very much for your assistance with this issue. Your expertise and deep knowledge are invaluable here, and I/and the community for sure greatly appreciate your involvement. Please feel free to add any additional insights or correct any points I might have missed or misunderstood.

from controller-runtime.

sbueringer avatar sbueringer commented on September 21, 2024

Thx for opening this issue and the feedback. In general makes sense to improve the feature where necessary.

One question. Are the issues identified above from the kube-rbac-proxy audit or from an audit of the current implementation in controller-runtime? I'm not sure if they all apply in CR, as we only implement a subset of the kube-rbac-features and we only use them specifically for the metrics endpoint (e.g. /healthz is entirely out of scope today)

from controller-runtime.

camilamacedo86 avatar camilamacedo86 commented on September 21, 2024

Hi @sbueringer,

IHMO all seems to apply because the feedback here in my understand is mainly keep the things configurable for properly inform the certs. Regards the Lack of support for alwaysAllow configurations for critical paths like /healthz and alwaysAllowGroups like system:masters. it seems that it could appear to work, but then cause metrics outages when networking to the kube-apiserver is flaky, which is one of the most important times to have metrics.

from controller-runtime.

k8s-triage-robot avatar k8s-triage-robot commented on September 21, 2024

The Kubernetes project currently lacks enough contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

  • After 90d of inactivity, lifecycle/stale is applied
  • After 30d of inactivity since lifecycle/stale was applied, lifecycle/rotten is applied
  • After 30d of inactivity since lifecycle/rotten was applied, the issue is closed

You can:

  • Mark this issue as fresh with /remove-lifecycle stale
  • Close this issue with /close
  • Offer to help out with Issue Triage

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

from controller-runtime.

camilamacedo86 avatar camilamacedo86 commented on September 21, 2024

/remove-lifecycle stale

from controller-runtime.

camilamacedo86 avatar camilamacedo86 commented on September 21, 2024

hi @sbueringer

Could we frozen this one?
Until someone be able to look on it and see if can address the enhancements?

from controller-runtime.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.