Главная
Study mode:
on
1
Intro
2
Mesos Migration to Kubernetes
3
Motivation: Initial K8s access-controls
4
Authorization Architecture Overview
5
Authorization Component: OPA Capabilities, User Groups, Service Metadata
6
Capability Example
7
Authorization Component: The Policy Manager
8
Authorization Component: Client side enforcement
9
Example run: Basic
10
Example run: team-based
11
Rollout Strategy
12
Challenges and Special Cases
13
System Reliability
14
Shortcomings and Future Improvements . Not every resource has meaning metadata labelsite.
15
Conclusions
Description:
Explore a comprehensive conference talk on implementing fine-grained user authorization for Kubernetes using Open Policy Agent (OPA) and LDAP. Dive into Yelp's journey of migrating from Mesos to Kubernetes and their innovative approach to overcoming authorization challenges. Learn about the shortcomings of existing Kubernetes authorization mechanisms and discover the design details of Yelp's new OPA-based system. Gain insights into strategies for provisioning authorization rules at scale, achieving zero-downtime migration, and addressing issues encountered along the way. Examine the authorization architecture, including OPA capabilities, user groups, and service metadata. Follow along with practical examples of basic and team-based authorization runs. Understand the rollout strategy, system reliability considerations, and potential future improvements for this advanced authorization solution.

Fine-Grained User Authorization for Kubernetes with OPA and LDAP

CNCF [Cloud Native Computing Foundation]
Add to list
0:00 / 0:00