Skip to content

Commit cc655f3

Browse files
admission-control: allow routesrv proxy
Allow engineers to read routes from routesrv service proxy. See also * #6497 * #9106 Signed-off-by: Alexander Yastrebov <[email protected]>
1 parent a698186 commit cc655f3

File tree

1 file changed

+10
-0
lines changed

1 file changed

+10
-0
lines changed

cluster/manifests/02-admission-control/teapot.yaml

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -575,6 +575,16 @@ webhooks:
575575
object.kind == "ConfigMap" &&
576576
object.metadata.name == "skipper-default-filters"
577577
)
578+
- name: 'allow-routesrv-routes-access'
579+
expression: |
580+
!(
581+
"okta:common/engineer" in request.userInfo.groups &&
582+
request.name == "skipper-ingress-routesrv" &&
583+
request.resource.resource == "services" &&
584+
request.subResource == "proxy" &&
585+
request.operation == "CONNECT"
586+
)
587+
578588
- name: collaborator-deny-admitter.teapot.zalan.do
579589
clientConfig:
580590
{{- if eq .Cluster.Provider "zalando-eks"}}

0 commit comments

Comments
 (0)