Skip to content

Add SubjectAccessReview resources (authorization.k8s.io/v1) #110

Description

@cuppett

Summary

Add support for the authorization review virtual resources: SubjectAccessReview, SelfSubjectAccessReview, SelfSubjectRulesReview, and LocalSubjectAccessReview.

Motivation

These resources enable programmatic authorization checks — "can user X perform action Y on resource Z?" Useful for building custom dashboards, RBAC auditing tools, and operator authorization logic.

Design Considerations

These are virtual, create-only resources — they do not persist and only support POST (create). They return an immediate response with the authorization decision. This is a fundamentally different pattern from standard CRUD resources.

Options:

  1. Standard resource classes that override/disable get/update/delete/watch
  2. Methods directly on KubernetesCluster (e.g., $cluster->canI(...))
  3. A CreateOnly marker interface that limits available operations

Effort: Medium (introduces create-only virtual resource pattern)

Triage update (2026-09-02)

Reshape around a safe create-only virtual-resource abstraction or a cluster-level canI() API before adding the four review types. Do not expose inherited get/update/delete/watch methods that Kubernetes does not support for these review APIs.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    architectureInternal architecture changeenhancementNew feature or requestresourceNew K8s resource typetier-3Advanced/specialized

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions