Uploaded image for project: 'Distributed Tracing'
  1. Distributed Tracing
  2. TRACING-3500

Allow running processors with special permissions with limited permissions (even getting less information)

XMLWordPrintable

    • Icon: Spike Spike
    • Resolution: Duplicate
    • Icon: Undefined Undefined
    • None
    • None
    • None
    • None

      Some users may want to use those processors that require special permissions to get, for instance, the list of pods from a namespace.

      This became a recurrent request in otel-collector Slack channel:

      Hello, is it possible to use the k8sclusterreceiver without a ClusterRole/Binding? For example to get all metrics for a given k8s namespace. Like the limited privilege deployment of kube-state-metrics ? thanks. Without that it (as expected) errors
      
      This also applies for processor/k8sattributesprocessor, where i'm only interested in collecting eg. pod info from namespace my collector is running in. Im not interested in setting up clusterwide rbac for that
      

      It would be interesting to allow the users to run those processors even when they will not get all the information.

              rhn-support-iblancas Israel Blancas Alvarez
              rhn-support-iblancas Israel Blancas Alvarez
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: