feat: enable omitting provider name prefix in rbac #134
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What this PR does / why we need it:
Binding to a pre-defined Group such as
system:authenticatedis currently not possible with AccessReqests, because the subject's name is always prefixed with the provider name. This PR adds a possibility to configure that the provider name prefix should be omitted.Which issue(s) this PR fixes:
None
Special notes for your reviewer:
Release note:
For subjects with kind `Group` or `User` in an `AccessRequest`'s `spec. oidc.roleBindings[*].subjects` entry, it is now possible to prefix the `name` with `::`. This will cause the ClusterProvider to just remove this prefix instead of applying the oidc provider name when creating (Cluster)RoleBindings out of this configuration. By using this method, it is now possible to bind to k8s-predefined Groups such as `system:authenticated` by specifying `::system:authenticated` as subject name, for example.