Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add support for user/group impersonation #371

Open
javanthropus opened this issue Dec 1, 2022 · 0 comments
Open

Add support for user/group impersonation #371

javanthropus opened this issue Dec 1, 2022 · 0 comments

Comments

@javanthropus
Copy link

My team runs clusters where we do not have a direct ClusterRoleBinding to the cluster-admin ClusterRole. We have granted ourselves the ability to impersonate users and set up a phony user that does have the ClusterRoleBinding. This forces us to do something akin to sudo when we want to perform risky operations.

In order to perform an administrative command, such as deleting a namespace, we can use kubectl like this:

kubectl delete ns example-ns --as phony-user

Please add support for doing user and group impersonation that leverages the standard k8s mechanisms linked above.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant