Skip to content

Limit access for Karmada to certain resources in member clusterΒ #6219

@ritzdevp

Description

@ritzdevp

Please provide an in-depth description of the question you have:

When a member cluster is registered with Karmada, there is a secret in the member cluster associated with a service account, which is used as the impersonator secret in Karmada. This service account gives Karmada full access to the member cluster for all resources. Is there a way to limit the resources and verbs that Karmada can have access to in a member cluster?

What do you think about this question?:
My guess is that this can be controlled by modifying the ClusterRole in the member cluster that is associated with the service account whose secret is used by Karmada. But I am wondering if this feature is already offered in karmadactl.

Environment:

  • Karmada version:
  • Kubernetes version:
  • Others:

Metadata

Metadata

Assignees

No one assigned

    Labels

    kind/questionIndicates an issue that is a support question.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions