-
Notifications
You must be signed in to change notification settings - Fork 603
Open
Labels
area/conformanceGateway API Conformance Related IssuesGateway API Conformance Related Issuesarea/installationhelp wantedExtra attention is neededExtra attention is needed
Milestone
Description
The documentation here: https://gateway-api.sigs.k8s.io/concepts/security-model/#roles-and-personas references personas that can use the gateway api
But the chart does not deploy any RBAC rules enabling any users but a cluster-admin to use the gateway api. This makes it very hard to use.
#4532 was a first stab at some rbac rules, but seems to have stalled, and did not use the personas or support all the modes defined by the gateway api.
We should add an option to the chart to select between no user rbac (existing behavior), 3-tier and 4-tier setups as described in:
Metadata
Metadata
Assignees
Labels
area/conformanceGateway API Conformance Related IssuesGateway API Conformance Related Issuesarea/installationhelp wantedExtra attention is neededExtra attention is needed