Send namespace header in MT components#7048
Merged
knative-prow[bot] merged 1 commit intoknative:mainfrom Jun 29, 2023
Merged
Conversation
Member
Author
|
/cc @matzew |
85f157b to
9d4b75d
Compare
Member
Author
|
/test upgrade-tests |
8d0051a to
d944e93
Compare
When running MT components in mesh mode with Istio, we lose the ability to define fine grained policies since we don't know the resource namespace that originated such request, therefore, by having a `Kn-Namespace` header, in mesh mode, users case define fine-grained policies and isolate namespaces. Signed-off-by: Pierangelo Di Pilato <pierdipi@redhat.com>
d944e93 to
14e4bea
Compare
Codecov ReportPatch coverage:
Additional details and impacted files@@ Coverage Diff @@
## main #7048 +/- ##
==========================================
- Coverage 78.75% 78.59% -0.17%
==========================================
Files 248 249 +1
Lines 13148 13228 +80
==========================================
+ Hits 10355 10396 +41
- Misses 2273 2304 +31
- Partials 520 528 +8
☔ View full report in Codecov by Sentry. |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: matzew, pierDipi The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
pierDipi
added a commit
to pierDipi/eventing
that referenced
this pull request
Jul 6, 2023
When running MT components [1] in mesh mode with Istio, we lose the ability to define fine grained policies since we don't know the resource namespace that originated such request, therefore, by having a `Kn-Namespace` header, in mesh mode, users case define fine-grained policies and isolate namespaces. [1] IMC, MTChannelBasedBroker, and PingSource Signed-off-by: Pierangelo Di Pilato <pierdipi@redhat.com>
openshift-merge-robot
pushed a commit
to openshift-knative/eventing
that referenced
this pull request
Jul 6, 2023
* Refactor PingSource adapter client creation (knative#6880) This is just a refactoring to make it easier to implement Eventing TLS Part of knative#6879 --------- Signed-off-by: Pierangelo Di Pilato <pierdipi@redhat.com> * Send namespace header in MT components (knative#7048) When running MT components [1] in mesh mode with Istio, we lose the ability to define fine grained policies since we don't know the resource namespace that originated such request, therefore, by having a `Kn-Namespace` header, in mesh mode, users case define fine-grained policies and isolate namespaces. [1] IMC, MTChannelBasedBroker, and PingSource Signed-off-by: Pierangelo Di Pilato <pierdipi@redhat.com> * Fix compile error Signed-off-by: Pierangelo Di Pilato <pierdipi@redhat.com> --------- Signed-off-by: Pierangelo Di Pilato <pierdipi@redhat.com>
vishal-chdhry
pushed a commit
to vishal-chdhry/eventing
that referenced
this pull request
Jul 6, 2023
When running MT components [1] in mesh mode with Istio, we lose the ability to define fine grained policies since we don't know the resource namespace that originated such request, therefore, by having a `Kn-Namespace` header, in mesh mode, users case define fine-grained policies and isolate namespaces. [1] IMC, MTChannelBasedBroker, and PingSource Signed-off-by: Pierangelo Di Pilato <pierdipi@redhat.com>
pierDipi
added a commit
to pierDipi/eventing
that referenced
this pull request
Jul 20, 2023
* Refactor PingSource adapter client creation (knative#6880) This is just a refactoring to make it easier to implement Eventing TLS Part of knative#6879 --------- Signed-off-by: Pierangelo Di Pilato <pierdipi@redhat.com> * Send namespace header in MT components (knative#7048) When running MT components [1] in mesh mode with Istio, we lose the ability to define fine grained policies since we don't know the resource namespace that originated such request, therefore, by having a `Kn-Namespace` header, in mesh mode, users case define fine-grained policies and isolate namespaces. [1] IMC, MTChannelBasedBroker, and PingSource Signed-off-by: Pierangelo Di Pilato <pierdipi@redhat.com> * Fix compile error Signed-off-by: Pierangelo Di Pilato <pierdipi@redhat.com> --------- Signed-off-by: Pierangelo Di Pilato <pierdipi@redhat.com>
pierDipi
added a commit
to pierDipi/eventing
that referenced
this pull request
Jul 20, 2023
* Refactor PingSource adapter client creation (knative#6880) This is just a refactoring to make it easier to implement Eventing TLS Part of knative#6879 --------- Signed-off-by: Pierangelo Di Pilato <pierdipi@redhat.com> * Send namespace header in MT components (knative#7048) When running MT components [1] in mesh mode with Istio, we lose the ability to define fine grained policies since we don't know the resource namespace that originated such request, therefore, by having a `Kn-Namespace` header, in mesh mode, users case define fine-grained policies and isolate namespaces. [1] IMC, MTChannelBasedBroker, and PingSource Signed-off-by: Pierangelo Di Pilato <pierdipi@redhat.com> * Fix compile error Signed-off-by: Pierangelo Di Pilato <pierdipi@redhat.com> --------- Signed-off-by: Pierangelo Di Pilato <pierdipi@redhat.com>
openshift-merge-robot
pushed a commit
to openshift-knative/eventing
that referenced
this pull request
Jul 20, 2023
* Refactor PingSource adapter client creation (knative#6880) This is just a refactoring to make it easier to implement Eventing TLS Part of knative#6879 --------- * Send namespace header in MT components (knative#7048) When running MT components [1] in mesh mode with Istio, we lose the ability to define fine grained policies since we don't know the resource namespace that originated such request, therefore, by having a `Kn-Namespace` header, in mesh mode, users case define fine-grained policies and isolate namespaces. [1] IMC, MTChannelBasedBroker, and PingSource * Fix compile error --------- Signed-off-by: Pierangelo Di Pilato <pierdipi@redhat.com>
This was referenced Jul 27, 2023
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
When running MT components [1] in mesh mode with Istio,
we lose the ability to define fine grained policies since we
don't know the resource namespace that originated such
request, therefore, by having a
Kn-Namespaceheader,in mesh mode, users case define fine-grained policies and
isolate namespaces.
[1] IMC, MTChannelBasedBroker, and PingSource