Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-5277

Users can create scoped robot accounts with cross-organization access

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Unresolved
    • Icon: Critical Critical
    • None
    • None
    • Quay
    • None
    • None
    • Product / Portfolio Work
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      1. Proposed title of this feature request

      Quay: users can create robot accounts that work across organizations

      2. What is the nature and description of the request?

      The robot accounts currently can only be created by org admins, who grant the desired permissions. This feature would allow regular users to create robot accounts, and assign the same or fewer permissions the user has, effectively working across organizations. The logs would indicate the user that is linked to the robot account, as it currently does with Applications. The user can select which specific organization and repositories the robot should have what kind of access to, including wildcards for both orgs and repositories. To prevent privilege escalation, the permission boundary of the robot is defined by the permissions of the user. So a superuser can create a robot with global read-only access to all orgs and repos, a regular user can only do that for repos and orgs they have access to.

      3. Why does the customer need this? (List the business requirements here)

       

      This would grant more flexibility to users, and the logging would have a better traceability/accountability of the actions performed by robot accounts.

              rhn-coreos-tunwu Tony Wu
              rhn-support-rauferna Raul Fernandez
              None
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated:
                None
                None