apache / apache/kvrocks-controller

Tracking Issue: Authentication and Authorization Roadmap

Open
#390 1 comment 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Go
Stars
141
Forks
76
PR merge metrics
No merged PRs in 30d

Description

Currently, controller lacks a permission management system, which poses significant security risks. This issue tracks the authentication and authorization roadmap for Kvrocks Controller.

## Direction

We plan to use [Casbin](https://github.com/apache/Casbin) for authz (authorization).

For authc (authentication), we plan to support third-party login or gateway authentication first. Local controller-managed users may be added later as a fallback or lightweight testing feature.

## Contribution Process

This roadmap is intentionally high-level. Contributors should design the concrete approach in the corresponding issue before implementation.

Before opening an implementation PR for any sub-task, please first post a proposal and wait for maintainer agreement. The proposal should describe the intended behavior, implementation steps, API and Web UI impact, storage and configuration impact, backward compatibility, security considerations, and test plan.

## Sub-issues

- [ ] Authc: OIDC and gateway authentication integration
- [ ] Authz: Casbin namespace RBAC
- [ ] Authc: Local users and sessions (#391, proposal required and deferred)
- [ ] Auth UI / Web UI integration

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.