-
Notifications
You must be signed in to change notification settings - Fork 981
Open
Labels
kind/questionIndicates an issue that is a support question.Indicates an issue that is a support question.
Description
Please provide an in-depth description of the question you have:
When a member cluster is registered with Karmada, there is a secret in the member cluster associated with a service account, which is used as the impersonator secret in Karmada. This service account gives Karmada full access to the member cluster for all resources. Is there a way to limit the resources and verbs that Karmada can have access to in a member cluster?
What do you think about this question?:
My guess is that this can be controlled by modifying the ClusterRole in the member cluster that is associated with the service account whose secret is used by Karmada. But I am wondering if this feature is already offered in karmadactl.
Environment:
- Karmada version:
- Kubernetes version:
- Others:
zhzhuang-zju
Metadata
Metadata
Assignees
Labels
kind/questionIndicates an issue that is a support question.Indicates an issue that is a support question.