Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[RFC] Multi-Tenant Workload Identity #5209

Draft
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

matheuscscp
Copy link
Member

@matheuscscp matheuscscp commented Feb 23, 2025

In this RFC we aim to add support for multi-tenant workload identity in Flux, i.e. the ability to specify at the object-level which set of cloud provider permissions must be used for interacting with the respective cloud provider on behalf of the reconciliation of the object. In this process, credentials must be obtained automatically, i.e. this feature must not involve the use of secrets. This would be useful in a number of Flux APIs that need to interact with cloud providers, including the source-controller, notification-controller, image-reflector-controller and image-automation-controller APIs.

@matheuscscp matheuscscp added the area/rfc Feature request proposals in the RFC format label Feb 23, 2025
@matheuscscp matheuscscp force-pushed the rfc-multi-tenant-workload-identity branch 2 times, most recently from b795adf to 3034741 Compare February 23, 2025 04:33
@stefanprodan stefanprodan changed the title [RFC-0010] Multi-Tenant Workload Identity [RFC] Multi-Tenant Workload Identity Feb 23, 2025
@stefanprodan stefanprodan marked this pull request as draft February 23, 2025 10:39
@matheuscscp matheuscscp force-pushed the rfc-multi-tenant-workload-identity branch 3 times, most recently from 4cf2d4f to 730835a Compare February 23, 2025 22:27
@matheuscscp matheuscscp force-pushed the rfc-multi-tenant-workload-identity branch from 730835a to dae4f23 Compare February 23, 2025 22:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/rfc Feature request proposals in the RFC format
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant