Skip to content

Limit Service Account permissions #3201

@peternied

Description

@peternied

For the initial release permissions for service accounts are going to be locked down so they only can be used with explicitly granted system indexes

Exit Criteria

  • modify authz workflow to filter out all permissions other than index permissions with system index grant
  • add/modify test case that confirms cluster-wide permissions are not accessible
  • add/modify test case where index permissions without system index grant is filtered out
  • add/modify test case where index permissions with system index grant is allowed (happy path)

Metadata

Metadata

Assignees

Labels

triagedIssues labeled as 'Triaged' have been reviewed and are deemed actionable.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions