Narrow Secret RBAC: per-namespace Roles and a restricted manager cache #8
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Decision (2026-10): stay cluster-wide for now; this tracks the follow-up.
Today
The chart default is a
ClusterRolewith full verbs onSecretsin every namespace, and the manager cache is unrestricted, so the firstGeton a Secret starts a cluster-wide Secret informer (list/watch everywhere). Anyone who compromises the operator pod or image can read every Secret in the cluster.rbac.namespaced: trueonly gives a Role in the release namespace, which cannot serve tenant namespaces (alert-source webhook Secrets). DESIGN.md §9 documents this.Where Secrets are touched after the redesign
<TerdutServer>-operator-key: in the TerdutServer's namespace (create/get/delete).<TerdutAlertSource>-terdut-webhook: in the alert source's namespace (create/get/delete,Owns).Proposal
watchNamespaces: []; render a Role + RoleBinding per listed namespace for Secrets/Deployments/Services/PDBs.cache.ByObjectfor those types) to them; keep CRDs/events/namespaces cluster-wide (namespacesgetonly, forallowedTeamsselectors).NamespaceNotEnabledcondition rather than a cache error.watchNamespaces: []meaning all namespaces with a ClusterRole, as an explicit single-tenant opt-in.rbac.namespacedtoggle.allowedTeamsenforceable by the cluster.