openshift / openshift/openshift-docs

[enterprise-4.11] Issue in file operators/admin/olm-creating-policy.adoc

Open
#51,078 4 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

lifecycle/frozen
Dominant language
HTML
Stars
883
Forks
2k
Avg merge
21h 5m
Merged PRs (30d)
737

Description

Which section(s) is the issue in?

Allowing non-cluster administrators to install Operators

What needs fixing?

The title of the section is misleading. The instructions there do not grant any permission to any user or group. They are about limiting permissions to an application, that is, to an operator. Operators run, by default, with full cluster administator privileges and these instructions show how to run an operator with more restrictive privileges.

Though runnig operators with limited privileges is necessary for the use case stated in the title, else "regular" users could use operators to escalate their own privileges, I cannot see instructions on how to enable non-cluster administrator users to install operators nor how the ensure these users can only run operators under restricted privileges.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with operators/admin/olm-creating-policy.adoc and the “Allowing non-cluster administrators to install Operators” section. Compare the section title with the instructions about restricting operator permissions, then determine whether the missing installation guidance is in scope. Done means the title and content accurately describe the procedure, including the permission boundaries for non-cluster administrators.

Written by the indexing model from the issue text.

Assessment

Domain
authorization, documentation
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.