Fine-Grained User Authorization for Kubernetes with OPA and LDAP
CNCF [Cloud Native Computing Foundation] via YouTube
Overview
Syllabus
Intro
Mesos Migration to Kubernetes
Motivation: Initial K8s access-controls
Authorization Architecture Overview
Authorization Component: OPA Capabilities, User Groups, Service Metadata
Capability Example
Authorization Component: The Policy Manager
Authorization Component: Client side enforcement
Example run: Basic
Example run: team-based
Rollout Strategy
Challenges and Special Cases
System Reliability
Shortcomings and Future Improvements . Not every resource has meaning metadata labelsite.
Conclusions
Taught by
CNCF [Cloud Native Computing Foundation]