NVIDIA / NVIDIA/OpenShell

Empty server.oidc.adminRole/userRole silently enables RBAC instead of authentication-only mode

Open
#3,045 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

state:triage-needed
Dominant language
Rust
Stars
8.7k
Forks
1.3k
Avg merge
2d 11h
Merged PRs (30d)
253

Description

User Story

As a cluster operator, I want to deploy OpenShell gateway in auth-only mode.

Problem Statement

values.yaml documents authentication-only mode thusly:

    # -- Role name for admin access. Leave empty (with userRole also empty) for
    # authentication-only mode. Both must be set or both empty.
    adminRole: ""
    # -- Role name for standard user access.
    userRole: ""

But the chart guards both keys on truthiness:

{{- if .Values.server.oidc.adminRole }}
admin_role    = {{ .Values.server.oidc.adminRole | quote }}
{{- end }}

so empty strings are omitted from the rendered TOML rather than emitted as "". OidcConfig then applies #[serde(default = "default_admin_role")], restoring openshell-admin / openshell-user. The gateway starts in RBAC mode with the stock role names.

Impact / Why This Matters

The chart provides no way to deploy in auth-only mode and its documentation is misleading.

Acceptance Criteria
  • Documentation is changed to reflect actual chart behavior.
  • Method to deploy in auth-only mode is added to the chart.
Reproduction Steps
  1. Install the chart with server.oidc.issuer set and server.oidc.adminRole / server.oidc.userRole left at their "" defaults.
  2. kubectl -n openshell get cm openshell-config -o yaml — the [openshell.gateway.oidc] table contains no admin_role or user_role key.
Environment

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with values.yaml and the Helm template that conditionally emits admin_role and user_role, then inspect OidcConfig and its default role behavior. Render or install the chart with both role values empty and inspect the generated ConfigMap. Done means the documentation matches the behavior and the chart provides a verified authentication-only deployment method.

Written by the indexing model from the issue text.

Assessment

Tech stack
helm, kubernetes, rust, yaml
Domain
authentication, devops, infrastructure
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
68/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.