The deploy bot lost one verb SEC-131

Open2 versionsKubernetes · Medium · Fix · about 30 min ·Linux + Kubernetes

Lab machine

A private machine with its own Kubernetes cluster. Starting takes about 30 seconds. Sessions last up to 60 minutes.
Priya Raman opened SEC-131 at 13:30SEV-3

Last week the deploy bot's cluster-wide edit role was replaced with a narrow Role. Since then every Waybill deploy fails. The release channel wants cluster-admin.

The new Role was written from memory, not from what the deploy job actually does. The CI log says exactly which request was refused.

"It gets exactly what the deploy job does. Not one verb more." (Priya)

kubectl auth can-i … --as=system:serviceaccount:<ns>:deploy-bot tests the bot's permissions without its token.

Your task

Grant the deploy bot exactly what the deploy job needs in its own namespace, by fixing manifests/rbac.yaml and applying it, then run the deploy job as the bot.

On the machine

  • ci/deploy-5120.log
  • manifests/rbac.yaml
  • kubectl auth can-i --as=…

Timeline

WedSEC-131: replace the bot's edit ClusterRoleBinding with a namespaced Role.
ThuDEP-820: every Waybill deploy fails (ci/deploy-5120.log).
13:30"Bind it to cluster-admin and let's move on." "Absolutely not."

Done when

  1. The bot can patch, get, and watch Deployments in its namespace.
  2. It cannot delete or create workloads, read Secrets, bind roles, or act in other namespaces.
  3. manifests/ matches the cluster.

Hints

Hint 1

The error names the verb, the resource, the API group, and the namespace. Read all four.

Hint 2

kubectl auth can-i with --as tests a ServiceAccount without its token, and --list shows everything it may do.

Hint 3

A Role rule grants verbs on resources within the API groups it names. Deployments live in apps, not in the core group.

Hint 4

Fix the existing rule so the deploy's one missing permission is granted, then apply the manifest.

Show the solution

Read `ci/deploy-5120.log`: the bot may not patch `deployments` in the `apps` group. Compare that with the rule in `manifests/rbac.yaml`. Either `patch` is missing from its verbs, or the rule names the core group `''` instead of `apps`. Fix the rule, apply it, confirm with `kubectl auth can-i patch deployments.apps --as=system:serviceaccount:<ns>:deploy-bot`, and check that delete and secrets are still denied.