Resolution: Done
Investigate reducing permissions to anonymous user
BU Product Work
Not Selected
To Do
OCPSTRAT-1378 - Reduced the permissions for anonymous users and groups
0% To Do, 0% In Progress, 100% Done
Removed Functionality
RedHat allows following roles for system:anonymous user and system:unauthenticated group:
oc get clusterrolebindings -o json | jq '.items[] | select(.subjects[]?.kind
== "Group" and .subjects[]?.name == "system:unauthenticated") |
.metadata.name' | uniq
Returns what unauthenticated users can do, which is the following:
Customers would like to minimize the allowed permissions to unauthenticated groups and users.
Workaround available: Gating the access with policy engines
Outcome: Minimize the allowed roles for unauthenticated access
Goals of spike:
- Investigate impact of disabling the roles listed above for new and existing clusters
- Document risks and feasibility
- causes
OCPBUGS-33453 Need auth to access public images
- Closed
- is blocked by
OCPBUGS-33378 Builds TestWebhook failed on step testing unauthenticated forbidden on upgrade
- Closed
- is related to
OCPBUGS-33041 Anonymous Users Cannot Trigger BuildConfig Webhooks
- Closed
- relates to
RFE-5312 Minimize permissions for unauthenticated user access to apiserver
- Approved
- links to