Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-7252

Enable User Impersonation via OpenShift Web Console

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • openshift-4.16
    • User Interface
    • False
    • None
    • False
    • Not Selected
    • Hide
      •  The customer assigns role bindings to groups and adds users to those groups instead of granting permissions directly to users.
      • When using the CLI (`oc` command) with `--as-user`, the API call includes the group (`groupname: subjectreview` and `system:authenticated`), and impersonation works as expected.
      • However, when attempting impersonation from the OpenShift Web Console (UI), the group is not included in the API request, making impersonation ineffective.
      Show
       The customer assigns role bindings to groups and adds users to those groups instead of granting permissions directly to users. When using the CLI (`oc` command) with `--as-user`, the API call includes the group (`groupname: subjectreview` and `system:authenticated`), and impersonation works as expected. However, when attempting impersonation from the OpenShift Web Console (UI), the group is not included in the API request, making impersonation ineffective.

      The customer is requesting an enhancement in OpenShift RBAC to allow users to impersonate other users when they are part of a group with the necessary role bindings via the OpenShift Web Console. Currently, this functionality is available using the CLI with `--as-user`, but no similar provision exists in the UI.

              amobrem Ali Mobrem
              rhn-support-sakkulka Sakshi Kulkarni
              Votes:
              1 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated: