Skip to content

Instantly share code, notes, and snippets.

@sbueringer
Last active June 23, 2019 17:26
Show Gist options
  • Save sbueringer/7a6ded69aff61523c0eef7e0b9ed64eb to your computer and use it in GitHub Desktop.
Save sbueringer/7a6ded69aff61523c0eef7e0b9ed64eb to your computer and use it in GitHub Desktop.
package authorization
test_deny_update_storageclass_ceph {
deny[{"id": id, "resource": {"kind": "storageclasses", "namespace": "", "name": "ceph"}, "resolution": resolution}] with data.kubernetes.storageclasses[""].ceph as {
"kind": "SubjectAccessReview",
"apiVersion": "authorization.k8s.io/v1beta1",
"spec": {
"resourceAttributes": {
"verb": "update",
"version": "v1",
"resource": "storageclasses",
"name": "ceph",
},
"user": "alice",
"group": ["user"],
},
}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment