Skip to content

Commit befdede

Browse files
committed
Propose namespaced IAM identities
In the [single cluster multitenancy] proposal, the functional requirement [FR4] introduced the use of cluster-wide resources, managed by the CAPI maintainers and hence preventing privilege escalation, through administrator review. In large organisations favouring autonomy, this brings high responsibility on the team operating CAPA. They need to judge which roles can be used in which namespaces. This breaks the autonomy principle those organisations have. In this situation, the current model introduces two sources to trust (the CAPA operator and the team operating it) and reduces the cluster operator autonomy to create clusters in new accounts. Goals --- 1. To enable AWSIdentity resources granting autonomy to cluster administrators to deploy clusters in their own accounts 2. To enable cluster administrators to allow of forbid AWSIdentities in their accounts
1 parent c383c6e commit befdede

File tree

1 file changed

+472
-0
lines changed

1 file changed

+472
-0
lines changed

0 commit comments

Comments
 (0)