Jason Fehr has submitted this change and it was merged. (
http://gerrit.cloudera.org:8080/24419 )
Change subject: IMPALA-15049: Harden Impala Kubernetes operator RBAC permissions
......................................................................
IMPALA-15049: Harden Impala Kubernetes operator RBAC permissions
Replace the operator's cluster-admin binding with least-privilege
ClusterRoles scoped to the CRD control plane and the namespaced resources
required by Helm reconcile.
Grant read-only CRD discovery permissions required by Kopf watches so
reconcile remains event-driven under tightened RBAC.
Remove namespace auto-create from reconcile and drop namespace create/get
permissions, because ImpalaCluster is namespaced and must target an
existing namespace.
Document the tightened RBAC model and optional-component permission notes
for LDAP-related resource kinds in the Kubernetes deployment guide.
Add a Helm --set list-index caveat so sparse extraArgs indices are avoided
and do not render blank arguments in container command lines.
Add unit tests that guard against reintroducing cluster-admin and validate
CR status/finalizer + CRD discovery permissions in the RBAC manifest.
Testing:
- python3 operator/impala-operator/tests/test_main.py
- python3 operator/impala-operator/tests/test_rbac_manifest.py
- python3 -m unittest discover -s operator/impala-operator/tests -p "test_*.py"
- python3 bin/jenkins/critique-gerrit-review.py --dryrun
- docker build -f operator/impala-operator/Dockerfile -t impala-operator:15049 .
- k3d image import impala-operator:15049 -c impala-live
- kubectl apply -k operator/impala-operator/manifests
- kubectl -n impala-operator-system set image deploy/impala-operator
operator=impala-operator:15049
- kubectl apply -n impala-rbac-live -f <ImpalaCluster core config>
- kubectl patch -n impala-rbac-live impalacluster impala-rbac-demo --type merge
-p '{"spec":{"ldapEnabled":true}}'
- kubectl patch -n impala-rbac-live impalacluster impala-rbac-demo --type merge
-p '{"spec":{"kuduEnabled":true,"rangerEnabled":true,"rangerAuthEnabled":true}}'
- kubectl delete -n impala-rbac-live impalacluster impala-rbac-demo --wait=true
(operator uninstalls both Helm releases)
- kubectl apply -n impala-exhaustive-live -f <ImpalaCluster with
ldap+kudu+ranger>
- python3 <LDAP impyla smoke script> (CREATE DATABASE, CREATE KUDU TABLE,
INSERT, SELECT)
Change-Id: Ia3eafc1f4ddcda423227ad5fc361e0bbbd4dad19
Assisted-by: GPT-5.3 (Cursor)
Reviewed-on: http://gerrit.cloudera.org:8080/24419
Reviewed-by: Gokul Kolady <[email protected]>
Reviewed-by: Jason Fehr <[email protected]>
Tested-by: Jason Fehr <[email protected]>
---
M helm/impala/README.md
M operator/impala-operator/main.py
M operator/impala-operator/manifests/rbac.yaml
M operator/impala-operator/requirements.txt
M operator/impala-operator/tests/test_main.py
A operator/impala-operator/tests/test_rbac_manifest.py
6 files changed, 156 insertions(+), 28 deletions(-)
Approvals:
Gokul Kolady: Looks good to me, but someone else must approve
Jason Fehr: Looks good to me, approved; Verified
--
To view, visit http://gerrit.cloudera.org:8080/24419
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings
Gerrit-Project: Impala-ASF
Gerrit-Branch: master
Gerrit-MessageType: merged
Gerrit-Change-Id: Ia3eafc1f4ddcda423227ad5fc361e0bbbd4dad19
Gerrit-Change-Number: 24419
Gerrit-PatchSet: 33
Gerrit-Owner: Anubhav Jindal <[email protected]>
Gerrit-Reviewer: Abhishek Rawat <[email protected]>
Gerrit-Reviewer: Anubhav Jindal <[email protected]>
Gerrit-Reviewer: Gokul Kolady <[email protected]>
Gerrit-Reviewer: Impala Public Jenkins <[email protected]>
Gerrit-Reviewer: Jason Fehr <[email protected]>