Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

improve rabc settings of secrets for yurt-manager component #1742

Merged

Conversation

rambohe-ch
Copy link
Member

What type of PR is this?

Uncomment only one /kind <> line, hit enter to put that in a new line, and remove leading whitespace from that line:
/kind bug
/kind documentation
/kind enhancement
/kind good-first-issue
/kind feature
/kind question
/kind design
/sig ai
/sig iot
/sig network
/sig storage

/kind enhancement

What this PR does / why we need it:

In order to improve the security setting for yurt-manager component, improve secret resource rbac settings for yurt-manager as following:

  1. move secret rbac settings from clusterrole to role
  2. secret rbac verbs only left update and get. remove other verbs like create and delete.

Which issue(s) this PR fixes:

Fixes #

Special notes for your reviewer:

Does this PR introduce a user-facing change?


other Note

@openyurt-bot
Copy link
Collaborator

@rambohe-ch: GitHub didn't allow me to assign the following users: your_reviewer.

Note that only openyurtio members, repo collaborators and people who have commented on this issue/PR can be assigned. Additionally, issues/PRs can only have 10 assignees at the same time.
For more information please see the contributor guide

In response to this:

What type of PR is this?

Uncomment only one /kind <> line, hit enter to put that in a new line, and remove leading whitespace from that line:
/kind bug
/kind documentation
/kind enhancement
/kind good-first-issue
/kind feature
/kind question
/kind design
/sig ai
/sig iot
/sig network
/sig storage

/kind enhancement

What this PR does / why we need it:

In order to improve the security setting for yurt-manager component, improve secret resource rbac settings for yurt-manager as following:

  1. move secret rbac settings from clusterrole to role
  2. secret rbac verbs only left update and get. remove other verbs like create and delete.

Which issue(s) this PR fixes:

Fixes #

Special notes for your reviewer:

Does this PR introduce a user-facing change?


other Note

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@openyurt-bot openyurt-bot requested review from Congrool and qclc October 23, 2023 15:24
@openyurt-bot openyurt-bot added approved approved size/L size/L: 100-499 labels Oct 23, 2023
@rambohe-ch rambohe-ch force-pushed the improve-yurt-manager-secret-rbac branch from 3aca9e4 to d04e580 Compare October 24, 2023 02:09
@codecov
Copy link

codecov bot commented Oct 24, 2023

Codecov Report

Merging #1742 (5b314d3) into master (0c1c982) will increase coverage by 0.06%.
The diff coverage is n/a.

@@            Coverage Diff             @@
##           master    #1742      +/-   ##
==========================================
+ Coverage   50.74%   50.80%   +0.06%     
==========================================
  Files         165      165              
  Lines       19258    19258              
==========================================
+ Hits         9772     9784      +12     
+ Misses       8566     8555      -11     
+ Partials      920      919       -1     
Flag Coverage Δ
unittests 50.80% <ø> (+0.06%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files Coverage Δ
...ntroller/yurtappdaemon/yurtappdaemon_controller.go 25.23% <ø> (ø)
...ger/controller/yurtappset/yurtappset_controller.go 47.28% <ø> (ø)
...coordinator/cert/yurtcoordinatorcert_controller.go 11.94% <ø> (ø)

... and 1 file with indirect coverage changes

@rambohe-ch rambohe-ch force-pushed the improve-yurt-manager-secret-rbac branch from d04e580 to 47c4f33 Compare October 24, 2023 07:08
@rambohe-ch rambohe-ch force-pushed the improve-yurt-manager-secret-rbac branch from 47c4f33 to 5b314d3 Compare October 24, 2023 07:34
@sonarqubecloud
Copy link

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
1.1% 1.1% Duplication

@rambohe-ch
Copy link
Member Author

@YTGhost PTAL

@rambohe-ch rambohe-ch requested a review from YTGhost October 24, 2023 08:40
Copy link
Member

@YTGhost YTGhost left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@openyurt-bot
Copy link
Collaborator

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: rambohe-ch, YTGhost

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kadisi kadisi merged commit 7c1198a into openyurtio:master Oct 24, 2023
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
approved approved lgtm lgtm size/L size/L: 100-499
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants