-
Story
-
Resolution: Done
-
Critical
-
ACM 2.16.0
-
Product / Portfolio Work
-
5
-
False
-
-
False
-
-
Not Selected
-
-
-
Workloads - Train 36 - 1, Workloads - Train 36 - 2
-
Important
-
None
Value Statement
ACM shipped these custom virt roles for 2.15:
kubevirt.io-acm-hub:admin
kubevirt.io-acm-hub:view
kubevirt.io-acm-managed:admin
kubevirt.io-acm-managed:view
We need to finalize them and make sure they are GA ready for 2.16. Some considerations are:
- security (least privilege)
- namespace vs cluster scoped resources
- should we combine into single roles or separate
- validate that no use cases are missing for a VM admin
Finalize with PM (Christian Stark) and architects (Joydeep + Josh)
Definition of Done for Engineering Story Owner (Checklist)
- ...
Development Complete
- The code is complete.
- Functionality is working.
- Any required downstream Docker file changes are made.
Tests Automated
- [ ] Unit/function tests have been automated and incorporated into the
build. - [ ] 100% automated unit/function test coverage for new or changed APIs.
Secure Design
- [ ] Security has been assessed and incorporated into your threat model.
Multidisciplinary Teams Readiness
- [ ] Create an informative documentation issue using the Customer
Portal Doc template that you can access from [The Playbook](
and ensure doc acceptance criteria is met.
- Call out this sentence as it's own action:
- [ ] Link the development issue to the doc issue.
Support Readiness
- [ ] The must-gather script has been updated.
- is documented by
-
ACM-29169 ACM 2.16 Fine-Grained RBAC General Doc Changes
-
- In Progress
-
-
ACM-29168 ACM 2.16 Fine-Grained RBAC Role Updates
-
- Closed
-
- is related to
-
ACM-26480 Add discoverable label for the kubevirt admin/view clusterroles
-
- Closed
-
-
ACM-26074 CNV version check fails despite having admin roles (RBAC)
-
- Closed
-
- relates to
-
ACM-27287 kubevirt.io-acm-managed:admin role is missing 'get' for 'secret'
-
- In Progress
-
-
ACM-26280 VM (on spoke) Configuration tab fails to configure for secrets/configmaps on Fleet UI
-
- Closed
-
-
ACM-26074 CNV version check fails despite having admin roles (RBAC)
-
- Closed
-
1.
|
Research and propose ACM virt roles reorganization for better UX |
|
Closed | |
Kurtis Wang |
|
||||||
2.
|
Implement ACM virt roles reorganization |
|
Closed | |
Unassigned |
|
||||||
3.
|
Update CNV-MTV addon to incorporate new ACM CNV role changes |
|
Closed | |
Unassigned |
|
||||||
4.
|
Create documentation task for updated ACM CNV roles |
|
Closed | |
Kurtis Wang |
|