W.I.P. configure external authorization policy#676
Draft
ensonic wants to merge 1 commit into
Draft
Conversation
b75ea23 to
2c4aaf3
Compare
34e7c1e to
b395459
Compare
ensonic
added a commit
that referenced
this pull request
May 19, 2026
This will let us add extra namespaces as needed. See PR #676
ensonic
added a commit
that referenced
this pull request
May 19, 2026
This will let us add extra namespaces as needed. See PR #676
ensonic
added a commit
that referenced
this pull request
May 19, 2026
This will let us add extra namespaces as needed. See PR #676
ensonic
added a commit
that referenced
this pull request
May 19, 2026
This will let us add extra namespaces as needed. See PR #676
ensonic
added a commit
that referenced
this pull request
May 19, 2026
This will let us add extra namespaces as needed. See PR #676
ensonic
added a commit
that referenced
this pull request
May 19, 2026
This will let us add extra namespaces as needed. See PR #676
Try to configure the AuthorizationPolicy for token vendor. This requires us to lift the constraint on chart assignments and we need to allow to deploy into the "defaul"t namespec as well. Tested: ```shell istioctl x authz check $(kubectl get pods -n default -l gateway.networking.k8s.io/gateway-name=crc-gateway -o name | cut -d'/' -f2) -n default istioctl proxy-config listener $(kubectl get pods -n default -l gateway.networking.k8s.io/gateway-name=crc-gateway -o name | cut -d'/' -f2) -n default --port 443 -o json | more ```
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Try to configure the AuthorizationPolicy for token vendor.
This requires us to lift the constraint on chart assignments and we
need to allow to deploy into the "defaul"t namespec as well.
Tested: