Managing RBAC Cross Multiple Kubernetes Clusters - Alena Prokharchyk, Rancher Labs, Inc.

preview_player
Показать описание


Managing RBAC Cross Multiple Kubernetes Clusters - Alena Prokharchyk, Rancher Labs, Inc.

Having several Kubernetes clusters in the organization quickly became de facto. The need could be driven by geographical separation, where clusters are located in different regions; or logical when cluster is dedicated to a particular team or department. With that comes a new challenge for an administrator - managing users and their permissions in heterogeneous Kubernetes cloud. During this session I want to share my team's experience building an open source authentication/authorization framework leveraging Kubernetes CRDs, that makes cross clusters auth and RBAC easy by having: * Multiple clusters, but single authentication and authorization point * Managing users RBAC permissions cross clusters, and automatic permission grant to the user * Effective way of grouping cluster's resources into manageable subsets to make RBAC/PodSecurity/NetworkPolicy application easier.

Рекомендации по теме