openshift-extends-k8s-authorization-model

Status: IN

OpenShift has dual authorization systems: its own authorization API group alongside the Kubernetes RBAC API, with OpenShift-specific resources (SCC, ClusterRoles like self-provisioner) layered on top.

Justifications

Parallel authorization APIs reflect OpenShift's extension of Kubernetes security model

Depends on (SL): ocp-two-authorization-api-groups, openshift-has-own-authorization-api, scc-api-group-security-openshift, default-clusterroles-list

Depended on by

JSON