-
Notifications
You must be signed in to change notification settings - Fork 517
☂️ [GEP-26] Workload Identity - Trust Based Authentication #9586
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
/assign @vpnachev |
/kind epic |
Current stateThe current proposal allows changing ProposalI propose that we make |
Uh oh!
There was an error while loading. Please reload this page.
How to categorize this issue?
/area security
/kind enhancement
This is an umbrella issue for implementing the changes proposed in GEP-26
Tasks
API Server
WorkloadIdentity
[GEP-26] AddWorkloadIdentity
API #9780CredentialsBinding
[GEP-26] AddCredentialsBinding
API #9626TokenRequest
[GEP-26] AddTokenRequest
API andworkloadidentities/token
subresource #9813SecretBinding
forCredentialsBinding
CredentialsBinding
instead ofSecretBinding
WorkloadIdentity
[GEP-26] Allow quota scope to reference WorkloadIdentity #10346CredentialsBinding
instead ofSecretBinding
WorkloadIdentity
[GEP-26] AddWorkloadIdentity
API #9780/token
subresource #10042TokenRequest
API andworkloadidentities/token
subresource #9813sub
claim value intoWorkloadIdentity
status [GEP-26] AddWorkloadIdentity
API #9780SecretBinding
in favor ofCredentialsBinding
shoot-dns-service
extensionAdmission Controller
CredentialsBindings
that they are responsible for:WorkloadIdentity
that they are responsible for:Controller Manager
Gardenlet
cloudprovider
secret with the workload identity annotations and metadata in the seed cluster [GEP-26] Cloudprovider secret can contain workload identity data #10239gardener.cloud/operation=renew-workload-identity-token
Operator
TokenRequest
API andworkloadidentities/token
subresource #9813/token
subresource #10042Discovery Server
Extensions
WorkloadIdentity
when the extension provider has not implemented support yet.AWS
WorkloadIdentity
resource: [GEP-26] Workload Identity support gardener-extension-provider-aws#1141Azure
WorkloadIdentity
resource [GEP-26] Workload Identity support gardener-extension-provider-azure#999azurerm
terraform provider to 3.47.0 [GEP-26] Update azurerm provider to 3.47.0 terraformer#156GCP
WorkloadIdentity
resource [GEP-26] Workload Identity support gardener-extension-provider-gcp#855Alicloud
WorkloadIdentity
resourceEnablement
CredentialsBinding
andWorkloadIdentity
[GEP-26] Grant gardener users with access to CredentialsBindings and WorkloadIdentities #10587Development Setup
Gardenctl
Dashboard
The text was updated successfully, but these errors were encountered: