Repository navigation
feat(auth): op-level IAM for EKS under --enforce-auth (AUTHZ-X1g-2) - #1540
Draft
NitinKumar004 wants to merge 6 commits into
Draft
NitinKumar004 wants to merge 6 commits into
NitinKumar004 wants to merge 6 commits into
Conversation
…er --enforce-auth
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #1495 (AUTHZ-X1g-2, EKS; Route 53 + CloudFront landed in #1536, API Gateway and execute-api:Invoke follow).
What changed
Under
cloudemu serve --enforce-auth, EKS is now authorized per operation on resource ARNs instead of at service level, so fine-grained and resource-scoped EKS policies work.classify(r) (opID, opArgs)thatServeHTTPandIAMChecks/IAMChecksWithContextboth use, so the authorized operation and resource are the ones that run. Requests classify cannot name get the handler's existing 4xx with no side effect (fail closed: shortcut principals get the error, policy users 403). 12 new auth-off golden cases were recorded on the base code and pass unchanged.eks:<Operation>.*: ListClusters, CreateCluster, ListAccessPolicies, DescribeAddonVersions, DescribeAddonConfiguration.arn:aws:eks:<region>:<account>:<kind>/<cluster>/<name>, built from the names dispatch uses. cloudemu's child ARNs have no trailing id (pre-existing shape), so the checked ARN is exactly the ARN the resource reports, and a missing child is checked on the same shape and still reaches its ResourceNotFoundException (the Terraform destroy waiters rely on this).access-entry/<cluster>/*.nodegroupName/addonName, else the cluster.eks:kubernetesVersion,eks:endpointPublicAccess,eks:endpointPrivateAccess,eks:authenticationMode,eks:bootstrapClusterCreatorAdminPermissions,eks:loggingType/<type>(CreateCluster, UpdateClusterConfig, UpdateClusterVersion as the SAR lists them);eks:principalArn,eks:accessEntryType,eks:username,eks:kubernetesGroups(CreateAccessEntry request, and from the stored entry on access-entry operations, pluseks:clusterName, which the SAR lists as an access-entry resource key);eks:policyArn,eks:accessScope,eks:namespaces(Associate / Disassociate);aws:RequestTag/*,aws:TagKeys,aws:ResourceTag/*. The cloudemu-onlytagsfield of UpdateClusterConfig also needseks:TagResource.X-Amzn-ErrorTypeplus{"code","message"}, the handler's own error shape).nodegroupName/addonName, so a nodegroup update could be read with cluster permission only. It now finds a nodegroup or add-on update only through that name and a cluster update only without one, as the EKS API Reference describes the parameter (required for a nodegroup or add-on update).iam:PassRolefor cluster, node, pod execution and service account roles (AUTHZ-X1k). The Kubernetes API of a cluster (/k8s/...) stays authn-only as before.EnforceAuthcomment, contrib/server README.Sources
servicereference.us-east-1.amazonaws.com/v1/eks/eks.json(actions, resource types, ARN formats, action and resource condition keys;eks:clusterNameis a key of the access-entry resource).eks:kubernetesVersionand others on CreateCluster, UpdateClusterConfig and UpdateClusterVersion.nodegroupName/addonNamerequired for nodegroup / add-on updates) and TagResource / ListTagsForResource errors (BadRequestException, NotFoundException).Verification
IAMChecksWithContexttable (actions, ARNs, condition keys, missing children), DescribeUpdate resource test, foreign tagging ARN SDK test.TestAuthzMatrixEKS(scoped cluster and nodegroup ARNs, missing nodegroup in scope gets 404, single Deny, ResourceTag and kubernetesVersion conditions, DescribeUpdate checked on the nodegroup, foreign tagging ARN),TestUnknownRESTOpHasNoSideEffectandTestOpLevelRESTHandlersAreResolversextended,TestAuthOffResponsesUnchanged(golden recorded on the base code).TestEnforceAuthEKSwith the real SDK.cloudemu serve --enforce-auth, scoped IAM user (eks:* on the e2e cluster and its children, Deny UpdateNodegroupVersion):--nodegroup-nameOK and without it ResourceNotFoundException; DescribeNodegroup of a missing nodegroup ResourceNotFoundException; deletes OK.aws eks update-kubeconfigagainst the cluster endpoint: get and create namespaces work, unaffected.aws_eks_cluster,aws_eks_node_group,aws_eks_addon: apply,plan -detailed-exitcode= 0, in-place nodegroup scaling update (UpdateNodegroupConfig + DescribeUpdate waiter), plan 0 again, destroy with the delete waiters.go build ./...,go vet,go test -raceon server/aws/eks, providers/aws/eks, server/aws, server/wire/..., persist;go -C contrib/server test -run Enforce; golangci-lint (new issues) 0;go generateno docs diff.