Azure / Azure/Azure-Spring-Apps
Fine grained RBAC / separation of concerns
- 主要语言
- 没有语言数据
- 星标
- 9
- 派生
- 11
- PR 合并指标
- 30 天内没有已合并 PR
描述
**Is your feature request related to a problem? Please describe.**
The [doc](https://learn.microsoft.com/en-us/azure/spring-apps/how-to-permissions) describes how to managed role permissions but this does not address a common scenario where a customer has 3 Teams A, B & C and where :
- Teams A should be allowed to deploy/undeploy App A ONLY, not App B, App C neither
- Teams B should be allowed to deploy/undeploy App B ONLY, not App A, App C neither
- Teams C should be allowed to deploy/undeploy App C ONLY, not App A, App B neither
**Describe the solution you'd like**
All the permissions listed in the doc should be more granular allowing to configure it at App Level
ASA should support an RBAC solution integrated with AAD , something like [what we have in AKS](https://learn.microsoft.com/en-us/azure/aks/azure-ad-rbac?tabs=portal)
This would require to deploy App to a specific namespace for each App. See [https://github.com/Azure/Azure-Spring-Apps/issues/21](https://github.com/Azure/Azure-Spring-Apps/issues/21)
**Describe alternatives you've considered**
None
**Additional context**
贡献指南
这个仓库没有索引到贡献指南
评估
这个 Issue 还没有评估数据。