Skip to content

Istio RBAC Improvements #6984

@liminw

Description

@liminw

Some improvements we can do for Istio RBAC:

   subjects:
   - properties:
     - key: request.auth.claims["group"]
       values: ["g1", "g2"]

(Authorization V2, #11800)

  • Support excludedValues for permissions and principals. For example:
  rules:
  - constraints:
    - key: destination.service
      excludedValues: ["secret.default.svc.cluster.local"]

(Authorization V2, #11712, #11800)

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions