Skip to content
体验新版
项目
组织
正在加载...
登录
切换导航
打开侧边栏
水淹萌龙
kubesphere
提交
aba51265
K
kubesphere
项目概览
水淹萌龙
/
kubesphere
与 Fork 源项目一致
Fork自
KubeSphere / kubesphere
通知
1
Star
0
Fork
0
代码
文件
提交
分支
Tags
贡献者
分支图
Diff
Issue
0
列表
看板
标记
里程碑
合并请求
0
DevOps
流水线
流水线任务
计划
Wiki
0
Wiki
分析
仓库
DevOps
项目成员
Pages
K
kubesphere
项目概览
项目概览
详情
发布
仓库
仓库
文件
提交
分支
标签
贡献者
分支图
比较
Issue
0
Issue
0
列表
看板
标记
里程碑
合并请求
0
合并请求
0
Pages
DevOps
DevOps
流水线
流水线任务
计划
分析
分析
仓库分析
DevOps
Wiki
0
Wiki
成员
成员
收起侧边栏
关闭侧边栏
动态
分支图
创建新Issue
流水线任务
提交
Issue看板
未验证
提交
aba51265
编写于
10月 10, 2019
作者:
K
KubeSphere CI Bot
提交者:
GitHub
10月 10, 2019
浏览文件
操作
浏览文件
下载
差异文件
Merge pull request #878 from wansir/update-iam-policy
update iam policy
上级
a8122a58
42e1b823
变更
2
隐藏空白更改
内联
并排
Showing
2 changed file
with
29 addition
and
2 deletion
+29
-2
pkg/controller/workspace/workspace_controller.go
pkg/controller/workspace/workspace_controller.go
+21
-0
pkg/models/iam/am.go
pkg/models/iam/am.go
+8
-2
未找到文件。
pkg/controller/workspace/workspace_controller.go
浏览文件 @
aba51265
...
...
@@ -560,6 +560,11 @@ func getWorkspaceAdmin(workspaceName string) *rbac.ClusterRole {
APIGroups
:
[]
string
{
"iam.kubesphere.io"
},
Resources
:
[]
string
{
"users"
},
},
{
Verbs
:
[]
string
{
"*"
},
APIGroups
:
[]
string
{
"openpitrix.io"
},
Resources
:
[]
string
{
"applications"
,
"apps"
,
"apps/versions"
,
"apps/events"
,
"apps/action"
,
"apps/audits"
,
"repos"
,
"repos/action"
,
"categories"
,
"attachments"
},
},
}
return
admin
...
...
@@ -588,6 +593,17 @@ func getWorkspaceRegular(workspaceName string) *rbac.ClusterRole {
ResourceNames
:
[]
string
{
workspaceName
},
Resources
:
[]
string
{
"workspaces/members"
},
},
{
Verbs
:
[]
string
{
"get"
,
"list"
},
APIGroups
:
[]
string
{
"openpitrix.io"
},
Resources
:
[]
string
{
"apps/events"
,
"apps/action"
,
"apps/audits"
},
},
{
Verbs
:
[]
string
{
"*"
},
APIGroups
:
[]
string
{
"openpitrix.io"
},
Resources
:
[]
string
{
"applications"
,
"apps"
,
"apps/versions"
,
"repos"
,
"repos/action"
,
"categories"
,
"attachments"
},
},
}
return
regular
...
...
@@ -605,6 +621,11 @@ func getWorkspaceViewer(workspaceName string) *rbac.ClusterRole {
ResourceNames
:
[]
string
{
workspaceName
},
Resources
:
[]
string
{
"workspaces"
,
"workspaces/*"
},
},
{
Verbs
:
[]
string
{
"get"
,
"list"
},
APIGroups
:
[]
string
{
"openpitrix.io"
},
Resources
:
[]
string
{
"applications"
,
"apps"
,
"apps/versions"
,
"repos"
,
"categories"
,
"attachments"
},
},
}
return
viewer
}
pkg/models/iam/am.go
浏览文件 @
aba51265
...
...
@@ -513,12 +513,16 @@ func GetWorkspaceRoleSimpleRules(workspace, roleName string) []models.SimpleRule
{
Name
:
"devops"
,
Actions
:
[]
string
{
"edit"
,
"delete"
,
"create"
,
"view"
}},
{
Name
:
"projects"
,
Actions
:
[]
string
{
"edit"
,
"delete"
,
"create"
,
"view"
}},
{
Name
:
"roles"
,
Actions
:
[]
string
{
"view"
}},
{
Name
:
"apps"
,
Actions
:
[]
string
{
"view"
,
"create"
,
"manage"
}},
{
Name
:
"repos"
,
Actions
:
[]
string
{
"view"
,
"manage"
}},
}
case
constants
.
WorkspaceRegular
:
workspaceRules
=
[]
models
.
SimpleRule
{
{
Name
:
"members"
,
Actions
:
[]
string
{
"view"
}},
{
Name
:
"devops"
,
Actions
:
[]
string
{
"create"
}},
{
Name
:
"projects"
,
Actions
:
[]
string
{
"create"
}},
{
Name
:
"devops"
,
Actions
:
[]
string
{
"view"
,
"create"
}},
{
Name
:
"projects"
,
Actions
:
[]
string
{
"view"
,
"create"
}},
{
Name
:
"apps"
,
Actions
:
[]
string
{
"view"
,
"create"
}},
{
Name
:
"repos"
,
Actions
:
[]
string
{
"view"
}},
}
case
constants
.
WorkspaceViewer
:
workspaceRules
=
[]
models
.
SimpleRule
{
...
...
@@ -527,6 +531,8 @@ func GetWorkspaceRoleSimpleRules(workspace, roleName string) []models.SimpleRule
{
Name
:
"devops"
,
Actions
:
[]
string
{
"view"
}},
{
Name
:
"projects"
,
Actions
:
[]
string
{
"view"
}},
{
Name
:
"roles"
,
Actions
:
[]
string
{
"view"
}},
{
Name
:
"apps"
,
Actions
:
[]
string
{
"view"
}},
{
Name
:
"repos"
,
Actions
:
[]
string
{
"view"
}},
}
}
...
...
编辑
预览
Markdown
is supported
0%
请重试
或
添加新附件
.
添加附件
取消
You are about to add
0
people
to the discussion. Proceed with caution.
先完成此消息的编辑!
取消
想要评论请
注册
或
登录