Close the review gaps from #1899: Cloud role gates, Helm write checks, no-access banner - #1971
Conversation
…ccess banner - Registered OCI chart sources are shared configuration that upgrade discovery resolves against: gate add/remove on the Cloud owner role, and hide the controls from non-owners. - Under Cloud, a request with no role group (the Hub's radar:system identity) is refused by role-gated endpoints instead of passing as OSS. - Key both per-user capability caches on username + groups, so a user who loses an IdP group can't reuse the verdict for up to a minute. These verdicts now decide Helm writes. - Map only Kubernetes denials to 403 for release reads; a chart repository's own 401/403 is not the caller's RBAC. - Log once per identity when Helm issue listing is forbidden, so missing Helm alerts leave a trace. - The no-access banner asks /auth/me?check=namespaces, which runs discovery, keeps its last definite answer through an undecided check, and polls until access is confirmed. - Helm actions stay disabled until the per-namespace check succeeds, including when it fails.
PR Summary by QodoClose Cloud authorization, Helm permission, and access-banner gaps
AI Description
Diagram
High-Level Assessment
Files changed (15)
|
Code Review by Qodo
1.
|
…e banner only for the current user
Follow-up to #1899: closes the gaps from its review. RAD-578.
Must-fix
radar:systemidentity passed owner-only settings. OSS behaviour is unchanged.Smaller fixes
/api/auth/me?check=namespaces, which runs namespace discovery, so it can't vanish when the permission cache expires. It keeps its last definite answer through a check that couldn't decide, and polls until access is confirmed.Tests
requireHelmWrite); the Cloud no-role deny; the owner gate on chart sources; repository 401/403 vs RBAC denial;Impersonate-Groupon streaming rollback; the banner's discovery path failing closed.go test(both modules),tsc, and web vitest pass.Verified on EKS (radar-test-nonprod), proxy auth with simulated users
viewerwhose IdP group grantseditin one namespace: Helm rollback and uninstall work there and are refused elsewhere. Dropping the group takes effect on the next request.Docs: skyhook-dev/radar-docs#129 (owner-only chart sources).
Note
Medium Risk
Changes authorization for Cloud config (OCI sources, no-tier denial) and Helm write caching keyed on groups; incorrect behavior would block legitimate admins or briefly allow stale permissions, but scope is bounded and covered by new tests.
Overview
Follow-up to #1899 that tightens Radar Cloud config auth, Helm/RBAC correctness, and the no-namespace-access UX.
Cloud config: Registered OCI chart sources are now owner-only in Cloud (
requireHelmSourceConfigWrite), with matching UI in the track-chart-source dialog. In Cloud mode, callers without aradar:owner|member|viewertier (e.g. Hubradar:system) are denied on tier-gated Radar config instead of bypassing the gate like OSS.RBAC caching & Helm: Per-user capability caches (including namespace Helm-write SARs) are keyed by username + groups via
IdentityCacheKey, so revoking an IdP group stops reusing stale “can write” for up to the TTL. Release read errors map to 403 only for Kubernetes RBAC (isReleaseReadForbidden), not chart-repo 401/403. Helm issues omit logging is once per identity when Secret list is forbidden.No-access banner:
/api/auth/me?check=namespacesruns namespace discovery; the banner polls that path, keeps the last booleannoNamespaceAccess, and Helm actions stay disabled while per-namespace write capability is unknown (helmWriteUnknown).Docs note owner-only chart sources and no-role Cloud denial on config.
Reviewed by Cursor Bugbot for commit 7c39b11. Bugbot is set up for automated code reviews on this repo. Configure here.