Summary
Add support for the authorization review virtual resources: SubjectAccessReview, SelfSubjectAccessReview, SelfSubjectRulesReview, and LocalSubjectAccessReview.
Motivation
These resources enable programmatic authorization checks — "can user X perform action Y on resource Z?" Useful for building custom dashboards, RBAC auditing tools, and operator authorization logic.
Design Considerations
These are virtual, create-only resources — they do not persist and only support POST (create). They return an immediate response with the authorization decision. This is a fundamentally different pattern from standard CRUD resources.
Options:
- Standard resource classes that override/disable get/update/delete/watch
- Methods directly on
KubernetesCluster (e.g., $cluster->canI(...))
- A
CreateOnly marker interface that limits available operations
Effort: Medium (introduces create-only virtual resource pattern)
Triage update (2026-09-02)
Reshape around a safe create-only virtual-resource abstraction or a cluster-level canI() API before adding the four review types. Do not expose inherited get/update/delete/watch methods that Kubernetes does not support for these review APIs.
Summary
Add support for the authorization review virtual resources:
SubjectAccessReview,SelfSubjectAccessReview,SelfSubjectRulesReview, andLocalSubjectAccessReview.Motivation
These resources enable programmatic authorization checks — "can user X perform action Y on resource Z?" Useful for building custom dashboards, RBAC auditing tools, and operator authorization logic.
Design Considerations
These are virtual, create-only resources — they do not persist and only support
POST(create). They return an immediate response with the authorization decision. This is a fundamentally different pattern from standard CRUD resources.Options:
KubernetesCluster(e.g.,$cluster->canI(...))CreateOnlymarker interface that limits available operationsEffort: Medium (introduces create-only virtual resource pattern)
Triage update (2026-09-02)
Reshape around a safe create-only virtual-resource abstraction or a cluster-level
canI()API before adding the four review types. Do not expose inherited get/update/delete/watch methods that Kubernetes does not support for these review APIs.