Julius von Kohout
Julius von Kohout
/close There has been no activity for a long time. Please reopen if necessary.
/close There has been no activity for a long time. Please reopen if necessary.
@lehrig feel free to join our security wg meetings and push this in the KFP meetings as well. We have to discuss a lot.
@rimolive You need to join the KFP meeting to push this PR.
closed due to inactivity
This is just crazy misconfiguration. Is your cluster missing pod security standards restricted for all namespaces?
@iptizer Here you can track the progress https://github.com/kubeflow/manifests/issues/2528 and here is the official proposal https://github.com/kubeflow/manifests/pull/2527
Can you join the next manifest WG meeting for discussion? It has been possible before. Can you use path based routing? Why do you not want the oidc-authservice token based...
@yurkoff-mv @ksgnextuple this looks more like introducing a security flaw than using proper tokens from serviceaccounts with oauth2-proxy. I am very open to merge something with proper authentication. CC @kromanow94