Skip to content

Commit 5f04745

Browse files
Merge pull request #9150 from zalando-incubator/admission-control/allow-routesrv-access
admission-control: allow routesrv proxy
2 parents be4ea4c + cc655f3 commit 5f04745

File tree

1 file changed

+10
-0
lines changed

1 file changed

+10
-0
lines changed

cluster/manifests/02-admission-control/teapot.yaml

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -575,6 +575,16 @@ webhooks:
575575
object.kind == "ConfigMap" &&
576576
object.metadata.name == "skipper-default-filters"
577577
)
578+
- name: 'allow-routesrv-routes-access'
579+
expression: |
580+
!(
581+
"okta:common/engineer" in request.userInfo.groups &&
582+
request.name == "skipper-ingress-routesrv" &&
583+
request.resource.resource == "services" &&
584+
request.subResource == "proxy" &&
585+
request.operation == "CONNECT"
586+
)
587+
578588
- name: collaborator-deny-admitter.teapot.zalan.do
579589
clientConfig:
580590
{{- if eq .Cluster.Provider "zalando-eks"}}

0 commit comments

Comments
 (0)