Skip to content

Kueue: plugin blocks non-admins from viewing namespaced Workloads/LocalQueues #1199

Description

@harsh-aghara

Describe the bug

The Kueue plugin prevents non-admin users from being able to view namespaced resources (Workloads, LocalQueues) in the UI, even though they do have the appropriate RBAC permissions to get and list those resources in their namespace.

Expected outcome:
Users who have RBAC permissions on a namespace should be able to view the lists of Workloads and LocalQueues, and Headlamp should automatically filter and show the resources for the namespaces to which they have access.

To Reproduce

Steps to reproduce the bug:

  1. Make a namespace and a service account, for example, data-scientist in the data-sci namespace.
  2. Make a Role that gives get, list, and watch permissions on workloads.kueue.x-k8s.io and localqueues.kueue.x-k8s.io.
  3. Use a namespace-scoped RoleBinding in the data-sci namespace to bind the Role to the service account.
  4. Log in to Headlamp using a token that has been generated for the data-scientist service account.
  5. In the left sidebar, click on Kueue.
  6. Click on the tab labelled Workloads.
  7. Look at the error message: "The Kubernetes credentials you currently have are not authorized to list this page."

Environment (please provide info about your environment):

  • Installation type: Linux Desktop App(using flatpak)
  • Headlamp Version: latest main
    Other: Kueue Plugin (version 0.1.0-alpha)

Can you fix this issue?

I'll submit a pull request to fix this bug.

Screenshots:

Image Image

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions