Andrew Block · @sabre1041
126 followers · 1069 posts · Server hachyderm.io

Latest release (v0.0.26) of the Group Sync Operator has been released! Features include:

* Certificate management for custom Azure certificates
* Security hardening for secret access

Now available in OperatorHub!

github.com/redhat-cop/group-sy

#openshift #security #RBAC

Last updated 1 year ago

Jérôme Petazzoni · @jpetazzo
1368 followers · 391 posts · Server hachyderm.io

In her second talk at today, @tiffanyfay walks us through a demo of setting up fine grained permissions with , creating roles, rolebindings, and even breaking down how kubectl obtains the service account token and discovers the kubernetes API server endpoint when running from within a pod!

#devoxx #kubernetes #RBAC

Last updated 2 years ago

Jérôme Petazzoni · @jpetazzo
1368 followers · 373 posts · Server hachyderm.io

À !

Et on va commencer par un talk de @tiffanyfay sur le dans , en anglais.

Je suis assez curieux de voir combien de gens vont venir écouter un talk en anglais !

(En tout cas si vous voulez un "quickstart" sur les permissions dans K8S, c'est THE occasion, ou comme on dit ici LE occasion :D )

#devoxx #RBAC #kubernetes

Last updated 2 years ago

robrich · @robrich
12 followers · 100 posts · Server hachyderm.io
Charlie Egan · @charlieegan3
26 followers · 37 posts · Server hachyderm.io

30 years on, remains a solid foundation for access control system designs.

I've written up a post where I go into detail about how to build and extend on RBAC in OPA.

styra.com/blog/enforcing-role-

#RBAC

Last updated 2 years ago

John Refior · @jrefior
146 followers · 1119 posts · Server hachyderm.io

So what do you think, role-based access control or attribute-based access control?

#RBAC #abac

Last updated 2 years ago

Greg Swift · @gregswift
52 followers · 84 posts · Server hachyderm.io

Say you run into the normal problems with groups:

1: Org restructuring has left groups in a constant mess
2: Groups are overloaded in who is in them and what access they provide
3: Groups are non-sensical and aren't following a pattern
4: Really want to get closer to () or ()

#zerostandingpermissions #zsp #rolebasedaccesscontrol #RBAC

Last updated 2 years ago

Volkan Özçelik · @volkan
27 followers · 1068 posts · Server z2h.dev

klum (Kubernetes Lazy User Manager) does the following basic tasks:

- Create/Delete/Modify users
- Easily manage roles associated with users
- Issues kubeconfig files for users to use

github.com/ibuildthecloud/klum

#klum #usermanagement #kubernetes #infra #RBAC #tools

Last updated 2 years ago

Volkan Özçelik · @volkan
27 followers · 1065 posts · Server z2h.dev

kubectl-who-can shows who has RBAC permissions to perform actions on different resources in Kubernetes.

github.com/aquasecurity/kubect

#kubernetes #RBAC #plugin #tools #devops #devex

Last updated 2 years ago

Volkan Özçelik · @volkan
27 followers · 1062 posts · Server z2h.dev

Krane is a Kubernetes RBAC static analysis & visualisation tool.

#krane #RBAC #security #visualization #StaticAnalysis #tools #devops #infra

Last updated 2 years ago

Volkan Özçelik · @volkan
23 followers · 987 posts · Server z2h.dev
Volkan Özçelik · @volkan
22 followers · 952 posts · Server z2h.dev

If you want to have a policy-based RBAC over “anything”, then OPA is a great solution

openpolicyagent.org/

#infra #security #RBAC #policy #opa #declarative #rego

Last updated 2 years ago

Volkan Özçelik · @volkan
16 followers · 821 posts · Server z2h.dev