Uploaded image for project: 'OpenShift Virtualization'
  1. OpenShift Virtualization
  2. CNV-52819

Migrations for cluster-admin only

XMLWordPrintable

    • only-cluster-admin-migrations
    • Product / Portfolio Work
    • 77
      • cluster-admins have permission to LM
      • namespaces admins do not have the permission to LM by default
      • a role exists to grant permissions to any user/group as opt-in
    • Green
    • Done
    • VIRTSTRAT-226 - Live migration to specific node
    • VIRTSTRAT-226Live migration to specific node
    • 0% To Do, 0% In Progress, 100% Done
    • Hide

      2025-06-16:
      Doc completed....

      Show
      2025-06-16: Doc completed....

      Goal

      Today, any namespace admin can create and trigger migrations.
      In order to avoid abuse, let's limit the triggering of migrations to cluster-admins.

      Before the change namespace admins (system:admin) can trigger migrations.
      After the change namespace admins can not trigger migrations.

      The reasoning is that moving VMs on the infra level, without impact to the user, is an infra admin - clsuter-admin - only task.

      User Stories

      • "As a cluster admin, I want to be the only human to trigger VM live migrations, so that nobody can abuse this mechanism.
      • another user story

      Non-Requirements

      • List of things not included in this epic, to alleviate any doubt raised during the grooming process.

      Notes

      • Any additional details or decisions made/needed

          1.
          upstream roadmap issue Sub-task Closed Normal Unassigned
          2.
          upstream design Sub-task Closed Normal Unassigned
          3.
          upstream documentation Sub-task Closed Normal Unassigned
          4.
          upgrade consideration Sub-task Closed Normal Unassigned
          5.
          CEE/PX summary presentation Sub-task Closed Normal Kedar Bidarkar
          6.
          test plans in polarion Sub-task Closed Normal Unassigned
          7.
          automated tests Sub-task Closed Normal Unassigned
          8.
          downstream documentation merged Sub-task Closed Normal Unassigned

              kbidarka@redhat.com Kedar Bidarkar
              fdeutsch@redhat.com Fabian Deutsch
              Akriti gupta Akriti gupta
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: