-
Notifications
You must be signed in to change notification settings - Fork 45
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
ui/oidc: Add 'groups' scope when requesting an id_token from Dex #2529
Conversation
In the scopes we request from Dex when retrieving and id_token to then authenticate to K8s API, we didn't include the 'groups' optional scope. This meant that apiserver couldn't retrieve the 'groups' claim from the generated token, hence the authenticated user wouldn't be able to assume roles based on Group-based (Cluster)RoleBindings. We add this scope to the `redux-oidc` manager configuration, and this resolves the issue. Fixes: #2526
Hello gdemonet,My role is to assist you with the merge of this Status report is not available. |
Branches have divergedThis pull request's source branch To avoid any integration risks, please re-synchronize them using one of the
Note: If you choose to rebase, you may have to ask me to rebuild |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM!
Integration data createdI have created the integration data for the additional destination branches.
The following branches will NOT be impacted:
You can set option
|
Waiting for approvalThe following approvals are needed before I can proceed with the merge:
Peer approvals must include at least 1 approval from the following list:
|
/approve |
In the queueThe changeset has received all authorizations and has been added to the The changeset will be merged in:
The following branches will NOT be impacted:
There is no action required on your side. You will be notified here once IMPORTANT Please do not attempt to modify this pull request.
If you need this pull request to be removed from the queue, please contact a The following options are set: approve |
I have successfully merged the changeset of this pull request
The following branches have NOT changed:
Please check the status of the associated issue None. Goodbye gdemonet. |
Component: ui
Context:
In the scopes we request from Dex when retrieving and id_token to then
authenticate to K8s API, we didn't include the 'groups' optional scope.
This meant that apiserver couldn't retrieve the 'groups' claim from the
generated token, hence the authenticated user wouldn't be able to assume
roles based on Group-based (Cluster)RoleBindings.
Summary:
We add this scope to the
redux-oidc
manager configuration, and thisresolves the issue.
Acceptance criteria:
See #2526 reproducing steps - group-based RBAC should be functional
Closes: #2526