-
Bug
-
Resolution: Done
-
Major
-
quay-v3.8.0
-
False
-
None
-
False
-
-
Description:
This is an issue of Quay 3.8.0 new feature "superuser full access", after enabled flag "FEATURE_SUPERUSERS_FULL_ACCESS: true", superuser can trigger and cancel build under normal user's namespace, but these operations can not be audited in the usage logs of normal user's organization. Pls review this issue.
Expected Deliverable: "any superuser action on tenant content can be audited"
Quay Image: quay-operator-bundle-container-v3.8.0-115
Superuser trigger the build under normal user's namespace:
Superuser cancel the build under normal user's namespace:
Check the usage logs:
The usage logs of normal user's organization:
- links to
- mentioned on
(6 mentioned on)