Adding permission framework integration to kubernetes proxy endpoint

Signed-off-by: Ruben Vallejo <rvallejo@vmware.com>
This commit is contained in:
Ruben Vallejo
2023-02-07 12:44:08 -05:00
parent 2bf94911a4
commit 1fef8423ce
10 changed files with 211 additions and 20 deletions
+1
View File
@@ -39,6 +39,7 @@
},
"dependencies": {
"@backstage/catalog-model": "workspace:^",
"@backstage/plugin-permission-common": "workspace:^",
"@kubernetes/client-node": "0.18.1"
},
"devDependencies": {
+5
View File
@@ -22,3 +22,8 @@
export * from './types';
export * from './catalog-entity-constants';
export {
kubernetesProxyReadPermission,
kubernetesProxyCreatePermission,
kubernetesClusterPermissions,
} from './permissions';
@@ -0,0 +1,39 @@
/*
* Copyright 2023 The Backstage Authors
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
import { createPermission } from '@backstage/plugin-permission-common';
/** This permission is used to authorize actions that involve using the kubernetes Proxy Endpoint /proxy
* @alpha
*/
export const kubernetesProxyReadPermission = createPermission({
name: 'kubernetes.proxy.read',
attributes: { action: 'read' },
});
export const kubernetesProxyCreatePermission = createPermission({
name: 'kubernetes.proxy.create',
attributes: { action: 'create' },
});
/**
* List of all cluster permissions.
* @alpha
*/
export const kubernetesClusterPermissions = [
kubernetesProxyReadPermission,
kubernetesProxyCreatePermission,
];