We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
End result: GitHub Actions should only be able to talosctl image pull (or kubectl run --rm --image blah:latest) and nothing else in the cluster.
talosctl image pull
kubectl run --rm --image blah:latest
Talos API currently lacks enough custom RBAC to restrict to specific API paths.
maybe build a webhook running in cluster that then execs talosctl with as lowest SA role as possible?
talosctl
The text was updated successfully, but these errors were encountered:
No branches or pull requests
End result: GitHub Actions should only be able to
talosctl image pull
(orkubectl run --rm --image blah:latest
) and nothing else in the cluster.Talos API currently lacks enough custom RBAC to restrict to specific API paths.
maybe build a webhook running in cluster that then execs
talosctl
with as lowest SA role as possible?The text was updated successfully, but these errors were encountered: