Azure / Azure/Azure-Spring-Apps

Fine grained RBAC / separation of concerns

Offen
#22 3 Kommentare 0 Reaktionen 1 zugewiesene Person Beansprucht von @yangtony90 Auf GitHub ansehen
Enhancement Tracking
Vorherrschende Sprache
Keine Sprachdaten
Sterne
9
Forks
11
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

**Is your feature request related to a problem? Please describe.**
The [doc](https://learn.microsoft.com/en-us/azure/spring-apps/how-to-permissions) describes how to managed role permissions but this does not address a common scenario where a customer has 3 Teams A, B & C and where :

- Teams A should be allowed to deploy/undeploy App A ONLY, not App B, App C neither
- Teams B should be allowed to deploy/undeploy App B ONLY, not App A, App C neither
- Teams C should be allowed to deploy/undeploy App C ONLY, not App A, App B neither

**Describe the solution you'd like**
All the permissions listed in the doc should be more granular allowing to configure it at App Level
ASA should support an RBAC solution integrated with AAD , something like [what we have in AKS](https://learn.microsoft.com/en-us/azure/aks/azure-ad-rbac?tabs=portal)

This would require to deploy App to a specific namespace for each App. See [https://github.com/Azure/Azure-Spring-Apps/issues/21](https://github.com/Azure/Azure-Spring-Apps/issues/21)

**Describe alternatives you've considered**
None

**Additional context**

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.