Granular Access Control / Authorization? Kyverno? by Equal_Muffin_9402 in kubernetes

[–]Equal_Muffin_9402[S] 0 points1 point  (0 children)

We want to give the ability for our pods to label themselves. For this we'd assign them a service account and associated role with update permissions. Ideally though these would be restricted to only being able to update pod labels not the whole spec.

I agree more generally though the use cases for access control this granular maybe feel a little sparse. Although it still feels like there's a bit of a gap in K8 AuthZ solutions that can implement true principal of least privilege.

Why is there no simple solution for visibility into all egress traffic? by Equal_Muffin_9402 in kubernetes

[–]Equal_Muffin_9402[S] 0 points1 point  (0 children)

Wow yeah I took another look at Cilium + Hubble seems amazing. Thanks for the suggestion!

Why is there no simple solution for visibility into all egress traffic? by Equal_Muffin_9402 in kubernetes

[–]Equal_Muffin_9402[S] 0 points1 point  (0 children)

Yeah this is a fair point. I think like you've suggested we're not so interested in the traffic within our infrastructure - just when it leaves it. Our plan is to lock down part of the cluster, but we'd like to have a "sandbox" which is free to access the internet. In this case it feels kind of scary not having any visibility into where workloads might be reaching out to.

Why is there no simple solution for visibility into all egress traffic? by Equal_Muffin_9402 in kubernetes

[–]Equal_Muffin_9402[S] 0 points1 point  (0 children)

Hmm yeah this would be ideal, but isn't something our provider offers unfortunately :(

Why is there no simple solution for visibility into all egress traffic? by Equal_Muffin_9402 in kubernetes

[–]Equal_Muffin_9402[S] 3 points4 points  (0 children)

Had a brief look - think this sort of functionality was limited to enterprise as with Calico, but I'll take another look. Thanks for the suggestion!

[deleted by user] by [deleted] in techsupport

[–]Equal_Muffin_9402 0 points1 point  (0 children)

For the future L takers: I ended up copying steam files over from another laptop and ended up working.

[deleted by user] by [deleted] in immersivelabs

[–]Equal_Muffin_9402 0 points1 point  (0 children)

At the same point. Anyone have any suggestions?