weave-gitops icon indicating copy to clipboard operation
weave-gitops copied to clipboard

docs: Delivery UI permissions

Open yiannistri opened this issue 3 years ago • 2 comments

What changed? Documentation

Why was this change made? To explain how to setup permissions for Delivery UI

How was this change implemented? N/A

How did you validate the change? N/A

Release notes N/A

Documentation Changes N/A

yiannistri avatar Aug 02 '22 19:08 yiannistri

@SamLR - if you have a chance to take a look at this PR that would be great - in particular, now that we the user permissions doc as well, whether you agree this is the right place for this content.

sympatheticmoose avatar Aug 03 '22 08:08 sympatheticmoose

The intention of this page wasn't so much in-depth discussion of which permissions were needed to run gitops and why (that's left to the service-account/user permission pages) but to cover a high level view of how to configure OIDC and kubernetes RBAC to work well with gitops.

With that said I think this should probably be split between either service-account and user pages or, possibly, a dedicated enterprise permissions page (as we should probably have similar documentation for the CAPI & policy features of enterprise)

SamLR avatar Aug 03 '22 10:08 SamLR

Just realised that we need to backport these to 0.9.1 onwards. Once we're happy with the content, I'll update previous versions.

yiannistri avatar Sep 12 '22 12:09 yiannistri

I can try to review by e.o.d Wednesday, but please don't hold on my account if someone else is able to review beforehand 👍

sympatheticmoose avatar Sep 12 '22 17:09 sympatheticmoose

additionally, a suggested update would be to reference this page from here as well https://docs.gitops.weave.works/docs/configuration/recommended-rbac-configuration/. In particular the note:

These recommendations are for Weave GitOps Core. A similar system can be used within Enterprise but it would need to be adapted to account for multi-cluster configurations and is beyond the scope of this document.

sympatheticmoose avatar Sep 15 '22 16:09 sympatheticmoose