-
Notifications
You must be signed in to change notification settings - Fork 5.3k
Open
Labels
area/rbacdesign proposalNeeds design doc/proposal before implementationNeeds design doc/proposal before implementationhelp wantedNeeds help!Needs help!
Description
It would be nice to be able to specify a RBAC policy based on the UID or GID of the downstream connection when it's coming through a unix socket.
This would involve exposing the UID/GID on the Connection if applicable. This would be done by using SO_PEERCRED to get the peer credentials from the socket.
A RBAC policy would then be added to read this data.
The use case we have in mind here is restricting certain routes to be available only to users that can assume a specific unix group.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
area/rbacdesign proposalNeeds design doc/proposal before implementationNeeds design doc/proposal before implementationhelp wantedNeeds help!Needs help!