You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
When the tenant is cordoned using capsule, we had a special check in webhook which verifies if a request to modify an object inside a tenant was made by Tenant owner or a service account.
But current realization had a problem - if access for a namespace inside a tenant was granted to the user using rolebindings created by tenant admin - the user will have permissions to modify objects (because he is not an owner of tenant)
The text was updated successfully, but these errors were encountered:
When the tenant is cordoned using capsule, we had a special check in webhook which verifies if a request to modify an object inside a tenant was made by Tenant owner or a service account.
But current realization had a problem - if access for a namespace inside a tenant was granted to the user using rolebindings created by tenant admin - the user will have permissions to modify objects (because he is not an owner of tenant)
The text was updated successfully, but these errors were encountered: