Uploaded image for project: 'Red Hat Advanced Cluster Management'
  1. Red Hat Advanced Cluster Management
  2. ACM-15086

[Spike] Investigate MCE components to identify RBAC manifests with wildcard permissions

XMLWordPrintable

    • Icon: Spike Spike
    • Resolution: Unresolved
    • Icon: Normal Normal
    • MCE 2.8.0
    • MCE 2.8.0
    • Installer
    • None
    • False
    • None
    • False
    • Hide

      Provide the required acceptance criteria using this template.
      * ...
      Show
      Provide the required acceptance criteria using this template. * ...
    • None

      Value Statement

      By looking into the RBAC manifests of MCE components to find wildcard permissions, we want to improve the security of our deployments. By pinpointing which components have excessive permissions, we can develop specific user stories for each component's squad, helping them manage permissions more effectively.

      Definition of Done for Engineering Story Owner (Checklist)

      • [ ] Create a complete list of MCE components, showing which ones have wildcard permissions in their RBAC manifests.
      • [ ] For each component with a wildcard, document the specific permissions it has and what might happen if we reduce those permissions.

      Development Complete

      • The code is complete.
      • Functionality is working.
      • Any required downstream Docker file changes are made.

      Tests Automated

      • [ ] Unit/function tests have been automated and incorporated into the
        build.
      • [ ] 100% automated unit/function test coverage for new or changed APIs.

      Secure Design

      • [ ] Security has been assessed and incorporated into your threat model.

      Multidisciplinary Teams Readiness

      Support Readiness

      • [ ] The must-gather script has been updated.

            Unassigned Unassigned
            dbennett@redhat.com Disaiah Bennett
            Kurtis Wang Kurtis Wang
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated: