cloudnative-pg / cloudnative-pg/plugin-barman-cloud
IAM-backed ObjectStores generate wildcard Secret RBAC
- Lenguaje dominante
- Go
- Estrellas
- 191
- Forks
- 72
- Merge medio
- 2 d 21 h
- PR fusionados (30 d)
- 21
Descripción
### Summary
When an `ObjectStore` uses AWS IAM role inheritance (`inheritFromIAMRole: true`) and does not reference any credential Secrets, the generated `-barman-cloud` Role still contains a `secrets` rule with no `resourceNames`.
In Kubernetes RBAC, an omitted or empty `resourceNames` list does not restrict the rule to no objects; it allows the verbs on all resources of that type. As a result, an IAM-backed barman-cloud instance can get/list/watch every Secret in the namespace even though barman-cloud does not need any Secret for the AWS credential chain.
### Why this matters
Deployments using IRSA, pod identity, or IMDS typically set `inheritFromIAMRole: true` so barman-cloud gets credentials from the pod environment. In that mode, barman-cloud returns before reading AWS credential Secret references, so the plugin should not grant Secret access unless a credential Secret is actually needed.
### Expected behavior
If no credential Secret names are collected for the ObjectStores referenced by a cluster, the generated Role should not include a `secrets` rule. For AWS credentials with `inheritFromIAMRole: true`, AWS Secret references should be ignored the same way Azure default/managed identity credentials are ignored today.
### Actual behavior
The Role includes a `secrets` rule with an empty `resourceNames` field, which grants access to all Secrets in the namespace.
### Proposed fix
- Skip AWS credential Secret references when `inheritFromIAMRole` is true.
- Omit the generated `secrets` PolicyRule when the collected Secret name set is empty.
- Keep the existing scoped `secrets` rule when explicit credential Secret refs are present.
Guía de contribución
Línea de trabajo
Empieza por las rutas de generación de Role y recopilación de referencias de credenciales de AWS, y compáralas con el manejo existente de identidades predeterminadas/administradas de Azure. Verifica el caso de herencia de IAM y el caso de un Secret de credenciales explícito, y añade o actualiza las pruebas para que la finalización implique que no haya ninguna regla de Secret para una colección vacía y que haya una regla con ámbito cuando existan nombres de Secret.
Escrito por el modelo de indexación a partir del texto del issue.
Evaluación
- Stack tecnológico
- aws, go, kubernetes
- Área
- authorization, backend, security
- Tipo de issue
- Error
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Estado de actividad
- Tranquilo
- Claridad
- Bien especificado
- Aptitud para principiantes
- 64/100