Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: add aggregated label to cluster role #50

Conversation

@j4ckstraw j4ckstraw force-pushed the add-aggregate-labels-to-cluster-role branch from a1cb0cf to b4f6e22 Compare December 3, 2024 03:41
@j4ckstraw j4ckstraw marked this pull request as draft March 10, 2025 08:20
@j4ckstraw j4ckstraw force-pushed the add-aggregate-labels-to-cluster-role branch from b4f6e22 to ac54307 Compare March 10, 2025 09:02
Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

merge viewer and editor into one file, make it more clear and tidy

metadata:
name: raycluster-viewer-role
labels:
rbac.authorization.k8s.io/aggregate-to-view: "true"
Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

according to https://github.com/kubernetes/kubernetes/blob/master/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/policy.go#L290C1-L291C1, and https://github.com/kubernetes/kubernetes/blob/master/plugin/pkg/auth/authorizer/rbac/bootstrappolicy/policy.go#L280 view clusterrole will aggregated to edit clusterrole, and edit clusterrole will aggregated to admin clusterrole, so only rbac.authorization.k8s.io/aggregate-to-view is enough.

- ray.io
resources:
- rayjobs
- rayjobs/status
Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

only operator can update/patch status subresource.

@j4ckstraw j4ckstraw marked this pull request as ready for review March 10, 2025 09:17
@j4ckstraw j4ckstraw force-pushed the add-aggregate-labels-to-cluster-role branch 2 times, most recently from 115b6fe to 31ec5fc Compare March 10, 2025 09:21
@j4ckstraw
Copy link
Author

j4ckstraw commented Mar 10, 2025

@kevin85421 @andrewsykim hello, Do you have time to take a look?

@j4ckstraw j4ckstraw force-pushed the add-aggregate-labels-to-cluster-role branch from 31ec5fc to ce8505f Compare March 10, 2025 12:02
@kevin85421
Copy link
Member

Hi @j4ckstraw, this repository is only updated whenever KubeRay is released. Could you open the PR on the KubeRay repository instead?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

non-cluster-admin user can't get rayclusters resource
2 participants