diff --git a/CHANGELOG.md b/CHANGELOG.md index f2af57404..13e2e361d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -8,6 +8,7 @@ ### Changed - Adapt webhook proxy to use HMAC ([#1403](https://github.com/opendevstack/ods-core/pull/1403)) +- Remove excesive permisions ([#1407](https://github.com/opendevstack/ods-core/pull/1407)) ### Fixed - Fixes VIT0089540 ([#1395](https://github.com/opendevstack/ods-core/pull/1395)) diff --git a/create-projects/create-projects.sh b/create-projects/create-projects.sh index 237a3d3e8..a7f41c8ee 100755 --- a/create-projects/create-projects.sh +++ b/create-projects/create-projects.sh @@ -85,7 +85,7 @@ fi if [ -n "${PROJECT_GROUPS}" ]; then echo "Seeding special permission groups (${PROJECT_GROUPS}) ..." - cd_usergroup_role="edit-atlassian-team" + cd_usergroup_role="view" usergroup_role="edit" admingroup_role="admin" readonlygroup_role="view" diff --git a/create-projects/tests/run.sh b/create-projects/tests/run.sh index 979604f9b..2bc2bf01b 100755 --- a/create-projects/tests/run.sh +++ b/create-projects/tests/run.sh @@ -77,7 +77,7 @@ oc mock --receive 'policy add-role-to-group view baz -n foo-cd' --times 1 oc mock --receive 'policy add-role-to-group edit foo -n foo-dev' --times 1 oc mock --receive 'policy add-role-to-group edit foo -n foo-test' --times 1 -oc mock --receive 'policy add-role-to-group edit-atlassian-team foo -n foo-cd' --times 1 +oc mock --receive 'policy add-role-to-group view foo -n foo-cd' --times 1 oc mock --receive 'policy add-role-to-group admin bar -n foo-dev' --times 1 oc mock --receive 'policy add-role-to-group admin bar -n foo-test' --times 1 diff --git a/ods-setup/setup-ods-project.sh b/ods-setup/setup-ods-project.sh index b20d5473f..31632312e 100755 --- a/ods-setup/setup-ods-project.sh +++ b/ods-setup/setup-ods-project.sh @@ -52,9 +52,6 @@ else oc new-project ${NAMESPACE} --description="Central ODS namespace with shared resources" --display-name="OpenDevStack" fi -# Allow system:authenticated group to view resources in central namespace -oc adm policy add-role-to-group view system:authenticated -n ${NAMESPACE} - # Create ods-edit service account and grant edit permissions if ! oc get serviceaccount ods-edit -n ${NAMESPACE} > /dev/null 2>&1; then echo "Creating service account 'ods-edit' ..." @@ -64,6 +61,20 @@ else echo "Service account 'ods-edit' already exists" fi +# Allow authenticated users to read the SonarQube and Aqua ConfigMaps +if ! oc get role configmap-reader -n ${NAMESPACE} > /dev/null 2>&1; then + oc create role configmap-reader \ + --verb=get \ + --resource=configmaps \ + --resource-name=sonarqube-scan \ + --resource-name=aqua \ + -n ${NAMESPACE} +else + echo "Role 'configmap-reader' already exists" +fi +oc adm policy add-role-to-group configmap-reader system:authenticated -n ${NAMESPACE} --role-namespace=${NAMESPACE} + + # Allow system:authenticated group to pull images from central namespace if ! oc adm policy add-cluster-role-to-group system:image-puller system:authenticated -n ${NAMESPACE}; then echo "You might not have enough rights to assign 'system:image-puller' to 'system:authenticated'." @@ -78,141 +89,6 @@ if ! oc adm policy add-cluster-role-to-user self-provisioner system:serviceaccou exit 1 fi -# Create a new role 'edit-atlassian-team' without secret-related resources access -if ! oc get clusterrole edit-atlassian-team > /dev/null 2>&1; then - echo "You might not have enough rights to create the new role 'edit-atlassian-team'." - echo "This script needs to be run by a cluster admin." - - # Create a temporary file - TEMP_FILE=$(mktemp 2>/dev/null || echo "/tmp/tempfile_$$") - - # Get the edit role YAML and rename it - oc get clusterrole edit -o yaml | sed 's/name: edit/name: edit-atlassian-team/' > $TEMP_FILE - - # Process the YAML to remove secret-related resources, empty sections, and metadata fields - PROCESSED_FILE=$(mktemp 2>/dev/null || echo "/tmp/tempfile_$$") - - awk ' - BEGIN { - skip_current_group = 0; - inside_api_group = 0; - api_group_buffer = ""; - skip_section = 0; - in_metadata = 0; - contains_secret = 0; - } - - # Skip metadata fields and sections - /creationTimestamp:/ || /resourceVersion:/ || /uid:/ { - next; - } - - # Detect start of aggregationRule section and skip it - /^aggregationRule:/ { - skip_section = 1; - next; - } - - # Detect end of aggregationRule section (when we see apiVersion) - /^apiVersion:/ { - skip_section = 0; - print $0; - next; - } - - # Track if we are in metadata section - /^metadata:/ { - in_metadata = 1; - print $0; - next; - } - - # Detect start of annotations or labels in metadata and skip them - /^ annotations:/ || /^ labels:/ { - if (in_metadata) { - skip_section = 1; - next; - } - } - - # Detect when we leave annotations or labels section (any line with single indent level) - /^ [a-zA-Z]/ { - if (skip_section && in_metadata && $0 !~ /^ annotations:/ && $0 !~ /^ labels:/) { - skip_section = 0; - } - } - - # Detect end of metadata section - /^[a-zA-Z]/ && in_metadata && $0 !~ /^metadata:/ { - in_metadata = 0; - } - - # Skip lines while in a section we want to skip - { - if (skip_section) { - next; - } - } - - # Detect API Groups line - /^- apiGroups:/ { - # If we were previously in an API group, print it if it wasnt being skipped and has no secrets - if (inside_api_group && !skip_current_group && !contains_secret && api_group_buffer != "") { - print api_group_buffer; - } - - # Reset variables for new group - inside_api_group = 1; - api_group_buffer = $0; - skip_current_group = 0; - contains_secret = 0; - - # Check if this apiGroup itself contains "secret" - if ($0 ~ /secret/ || $0 ~ /external-secrets\.io/) { - skip_current_group = 1; - } - next; - } - - # Look for resources section that might contain secrets - /^ resources:/ { - api_group_buffer = api_group_buffer "\n" $0; - next; - } - - # Check for secret in resource names - /^ - / && inside_api_group { - # If this resource contains "secret", mark the group for skipping - if ($0 ~ /secret/) { - contains_secret = 1; - } - api_group_buffer = api_group_buffer "\n" $0; - next; - } - - # Process all other lines - { - if (inside_api_group) { - # Add to buffer - api_group_buffer = api_group_buffer "\n" $0; - } else { - # Not in an API group, print directly - print $0; - } - } - - END { - # Print the last API group if it wasnt being skipped and has no secrets - if (inside_api_group && !skip_current_group && !contains_secret && api_group_buffer != "") { - print api_group_buffer; - } - }' $TEMP_FILE > $PROCESSED_FILE - - # Create the role and clean up - oc create -f $PROCESSED_FILE - rm $TEMP_FILE $PROCESSED_FILE -fi - # Create cd-user secret cd ${SCRIPT_DIR}/ocp-config/cd-user ${TAILOR} -n ${NAMESPACE} apply ${NON_INTERACTIVE} ${REVEAL_SECRETS}