docs: document the Kubernetes backend and its RBAC requirements - #120
Conversation
The README had no Kubernetes content, yet the Enterprise AIO chart docs point here for the required RBAC setup. Document the HP_K8S_* variables and the complete permission set, derived from every Kubernetes API call the agent makes. Signed-off-by: Oleksandr Piskun <oleksandr2088@icloud.com>
450b70f to
ec1947c
Compare
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. 📝 WalkthroughWalkthroughREADME.md clarifies which Kubernetes exposure types create a Priority: ⬇️ Low Merge Risk: 🟡 Moderate · up to Kubernetes deployments can expose credentials over HTTP or lose routing recovery after restart, while registry credentials may not apply to every Pod as documented. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 1 system. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 4
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Advanced
Run ID: 10825994-43eb-4221-bddc-a149a230a36f
📒 Files selected for processing (1)
README.md
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.
Signed-off-by: Oleksandr Piskun <oleksandr2088@icloud.com>
There was a problem hiding this comment.
Actionable comments posted: 2
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Advanced
Run ID: 9d6ae48e-8e2c-4eb6-8f13-dd78c8c5bf58
📒 Files selected for processing (1)
README.md
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.
Signed-off-by: Oleksandr Piskun <oleksandr2088@icloud.com>
This adds a
## Kubernetes Backendsection between the Docker engine section and "Adapting ExApps to use HaRP".HP_K8S_*variables, including how HaRP reaches and authenticates against the API server (HP_K8S_API_SERVERshould behttps, the token and its lifetime,HP_K8S_CA_FILE,HP_K8S_VERIFY_SSL), in-cluster versus out-of-cluster.RoleandRoleBinding, the namespace and service account they assume, plus a table explaining what each verb is used for. TheRoleBindinglives in the ExApp namespace and binds the service account of the HaRP pod, which usually lives in another namespace.nodes. Why that one cluster-scoped permission exists and when it can be omitted: HaRP lists nodes whenevernodeportexposure is in use, also when an ExApp is enabled and after every restart, so a fixed--k8s_upstream_hostdoes not remove the need for it. AClusterRoleandClusterRoleBindingare included.defaultservice account, and what that means forimagePullSecretsand the image pull policy (IfNotPresent, orNeverfor alocalregistry mapping since feat(k8s): accept image_pull_policy in the create payload #122).The permission set
Derived by enumerating every
_k8s_request()call site inhaproxy_agent.pyand its enclosing function, not from guesswork. It is complete for the current agent, including the/inforeachability probe, which reads the discovery endpoint/apithat every authenticated identity may read:apps/deploymentsget,list,create,patch,deleteservicesget,list,create,delete(createanddeleteare not used formanualexposure,getandlistare)persistentvolumeclaimscreate,deletepodslistnodes(cluster-scoped)list- only fornodeportexposure