Admit the platform to the group read paths - #10
Merged
Conversation
The Orchestrator resolves an agent's groups to build its workload, and is not a member of the organization that agent belongs to. It used to send that agent's own id as the caller to get past the membership check -- a platform service claiming to be the thing it manages. As itself it carries cluster admin, and that is what admits it. The type on the metadata settles nothing; the tuple behind it does. Reads only. Deciding who is in a group stays with the organization owner, and the write paths are untouched. Also adds the devspace config this repo had none of, so it can be run from source like its neighbours.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The Orchestrator resolves an agent's groups to build its workload and is not a member of that agent's organization. It used to send the agent's own id as the caller to get past the membership check.
As itself it carries cluster admin, and that is what admits it — verified against the tuple, not taken from the header. Reads only; the owner-gated write paths are untouched and tested to stay that way.
Also adds the devspace config this repo lacked, so it can run from source like its neighbours.