Uploaded image for project: 'Red Hat OpenShift AI Engineering'
  1. Red Hat OpenShift AI Engineering
  2. RHOAIENG-3747

Declarative Authorization rules

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • None
    • Platform
    • False
    • Hide

      None

      Show
      None
    • False
    • RHOAISTRAT-41 - Support SSO for all RHOAI components
    • No
    • No
    • Testable

      This user story outlines the creation of a declarative authorization rule framework for the RHOAI platform, leveraging label selectors to link authorization rules with cluster components such as services effectively.

      The central piece is the AuthRule, a data structure intended for simplifying the application of authorization policies.

      This resource should initially support:

      • rules for Kubernetes SubjectAccessReview (aiming for feature parity with Authorino's AuthConfig)
      • encompass a list of hosts it applies to, ensuring targeted policy enforcement.
      • ability to exclude certain paths from applying the auth(z) rules

      Acceptance Criteria:

      1. Developers can define AuthRule as using a declarative syntax, incorporating label selectors for direct linkage to cluster components.
      2. AuthRule supports the definition of Kubernetes SubjectAccessReview rules and includes a specification for applicable hosts.

            Unassigned Unassigned
            bartosz-1 Bartosz Majsak
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated: