You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Allowing non-cluster administrators to install Operators
What needs fixing?
The title of the section is misleading. The instructions there do not grant any permission to any user or group. They are about limiting permissions to an application, that is, to an operator. Operators run, by default, with full cluster administator privileges and these instructions show how to run an operator with more restrictive privileges.
Though runnig operators with limited privileges is necessary for the use case stated in the title, else "regular" users could use operators to escalate their own privileges, I cannot see instructions on how to enable non-cluster administrator users to install operators nor how the ensure these users can only run operators under restricted privileges.
The text was updated successfully, but these errors were encountered:
Mark the issue as fresh by commenting /remove-lifecycle stale.
Stale issues rot after an additional 30d of inactivity and eventually close.
Exclude this issue from closing by commenting /lifecycle frozen.
If this issue is safe to close now please do so with /close.
Mark the issue as fresh by commenting /remove-lifecycle stale.
Stale issues rot after an additional 30d of inactivity and eventually close.
Exclude this issue from closing by commenting /lifecycle frozen.
If this issue is safe to close now please do so with /close.
openshift-cibot
added
lifecycle/frozen
Indicates that an issue or PR should not be auto-closed due to staleness.
and removed
lifecycle/stale
Denotes an issue or PR has remained open with no activity and has become stale.
labels
Mar 30, 2023
Which section(s) is the issue in?
Allowing non-cluster administrators to install Operators
What needs fixing?
The title of the section is misleading. The instructions there do not grant any permission to any user or group. They are about limiting permissions to an application, that is, to an operator. Operators run, by default, with full cluster administator privileges and these instructions show how to run an operator with more restrictive privileges.
Though runnig operators with limited privileges is necessary for the use case stated in the title, else "regular" users could use operators to escalate their own privileges, I cannot see instructions on how to enable non-cluster administrator users to install operators nor how the ensure these users can only run operators under restricted privileges.
The text was updated successfully, but these errors were encountered: