To high access level RBAC needed to start workflow with TemplateRef #11861
Labels
area/workflow-templates
problem/more information needed
Not enough information has been provide to diagnose this issue.
problem/stale
This has not had a response in some time
type/support
User support issue - likely not a bug
Summary
Right now when we have workflowtemplate with reference to another workflowTemplate/clusterWorkflowTemplate we need to give access to user to all of them. In our case we want developers only can execute main workflowTemplate without giving access to lower level template which are more generic and can do something we dont want be executed by user. Lower level templates should be included with workflow service account not with user service account privileges.
Use Cases
EG When we have such template in workflow:
We want to developers use/create only their high level workflows, which will restart DB only for their team/cluster (team1 environment) not for others, what is available with more generic low level template. Right now to create workflow devs need "Create", "list", "Get" access to all workflowTemplates/clusterWorkflowTemplates used in template including refered ones, not only to higher one. It could be good lower level templates will be included with service account of pod not during start with devs user account. That will make configuration of RBAC more flexible without forcing accesses which user/account dont need.
Message from the maintainers:
Love this enhancement proposal? Give it a 👍. We prioritise the proposals with the most 👍.
The text was updated successfully, but these errors were encountered: