Skip to content

Extend aggregated user-facing ClusterRoles to all custom resources - #3197

Open
cwrau wants to merge 1 commit into
zalando:masterfrom
cwrau:feat/rbac/aggregate-view
Open

cwrau wants to merge 1 commit into
zalando:masterfrom
cwrau:feat/rbac/aggregate-view

Conversation

@cwrau

@cwrau cwrau commented Oct 7, 2026

Copy link
Copy Markdown

Problem description

The aggregated user-facing ClusterRoles (:users:view, :users:edit, :users:admin, aggregated into the builtin view, edit and admin roles through the rbac.authorization.k8s.io/aggregate-to-* labels) only cover postgresqls. Users who are bound to the builtin roles cannot see or manage postgresteams, operatorconfigurations or fabriceventstreams without hand-written RBAC. In the Helm chart the roles are also only created when rbac.createAggregateClusterRoles is enabled, and it defaults to false.

This keeps the existing three roles, names and labels and extends them:

  • postgresteams and operatorconfigurations: get/list/watch in view, edit and admin (the builtin edit and admin roles do not inherit view, so read access is repeated there); write verbs in admin only, because they change operator-wide behaviour and database role membership.
  • fabriceventstreams (group zalando.org): same access as postgresqls (read in view, write in edit and admin). The rule is now rendered unconditionally instead of only with enableStreams; RBAC rules for a resource whose CRD is not installed are harmless.
  • rbac.createAggregateClusterRoles now defaults to true in the chart. This is a behaviour change on upgrade: the three ClusterRoles are created and cluster users bound to the builtin roles gain the access above. Set it to false to keep the old behaviour. Anyone who already applied manifests/user-facing-clusterroles.yaml by hand under the same names should be aware of the name overlap when Helm tries to create them.
  • manifests/user-facing-clusterroles.yaml carries the same rules as the chart template.
  • docs/administrator.md describes the new coverage and default, drops the statement that the streams rules are only included with enableStreams, and fixes the role name (users, not user).

Existing view access to postgresqls is unchanged, nothing is narrowed.

Linked issues

Fixes #3196

Checklist

Thanks for submitting a pull request to the Postgres Operator project.
Please, ensure your contribution matches the following items:

  • Your go code is formatted. Your IDE should do it automatically for you. (no Go changes)
  • You have updated generated code when introducing new fields to the acid.zalan.do api package. (not applicable, no API changes)
  • New configuration options are reflected in CRD validation, helm charts and sample manifests. (not applicable, no new options, only a changed default)
  • New functionality is covered by unit and/or e2e tests. (not covered, the repo has no chart tests; checked with helm lint and helm template for the default values, rbac.createAggregateClusterRoles=false and enableStreams=true)
  • You have checked existing open PRs for possible overlay and referenced them. (no overlapping open PR found)

Signed-off-by: Chris Werner Rau <cwrau@cwrau.info>
@cwrau

cwrau commented Oct 7, 2026

Copy link
Copy Markdown
Author

For the label check; I would say this is a minor change, it's not a fix and it's not breaking anything

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Extend aggregated user-facing ClusterRoles to all custom resources

1 participant