Uploaded image for project: 'OpenShift Logging'
  1. OpenShift Logging
  2. LOG-3855

Evaluate possible solutions for fine-grained per-namespace logs access

XMLWordPrintable

    • Icon: Spike Spike
    • Resolution: Done
    • Icon: Major Major
    • None
    • None
    • Log Storage
    • None
    • 2
    • False
    • None
    • False
    • NEW
    • OBSDA-296 - Better control over access to logs in LokiStack for enterprise environments
    • NEW
    • Log Storage - Sprint 234, Log Storage - Sprint 235

      Problem Statement

      To properly support enterprise environments (See OBSDA-296) the cluster administrators in such clusters require to apply RBAC control over LokiStack to support the following three use cases

      • Support denying users to access the workload logs of an entire namespace.
      • Support denying users with elevated rights similar to cluster-admins to access the workload logs.
      • Support limiting users with elevated across many namespaces to access only logs where they are namespace admins.

      Developer Notes

      • Provide an enhancement proposal if needed to support the above via RBAC only.

              spad09 Shweta Padubidri
              ptsiraki@redhat.com Periklis Tsirakidis
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: