Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Workload Identity function #3521

Open
johnbelamaric opened this issue Aug 30, 2022 · 1 comment
Open

Workload Identity function #3521

johnbelamaric opened this issue Aug 30, 2022 · 1 comment
Labels
area/porch enhancement New feature or request triaged Issue has been triaged by adding an `area/` label

Comments

@johnbelamaric
Copy link
Contributor

We now have an operator for annotating a KSA for Workload Identity (#3456). This is helpful when the KSA lives in the Porch cluster. But it's not helpful for KSAs that are in the workload clusters that do not have Porch running.

Some examples:

I think we just need a function to do this. At least, that is true in the case of a 1:1 relationship between the deployment repository and the workload cluster. Or maybe more accurately, it is true if the project-id of all clusters reading from a given deployment repository is the same. See #3456 (comment) for a little more context.

@johnbelamaric johnbelamaric added the enhancement New feature or request label Aug 30, 2022
@johnbelamaric
Copy link
Contributor Author

Actually it seems this is not what the operator does; rather it handles only the GCP side of the binding. So this raises the priority of this issue.

@mortent mortent added triaged Issue has been triaged by adding an `area/` label area/porch labels Nov 15, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/porch enhancement New feature or request triaged Issue has been triaged by adding an `area/` label
Projects
None yet
Development

No branches or pull requests

2 participants