Role-Based Authorization
Rol Bazlı Yetkilendirme (RBAC)
Poyraz-K8s uses the powerful Casbin Engine to implement extremely granular, multi-dimensional security policies. Unlike standard Kubernetes RBAC, Poyraz RBAC is fully "Cluster-Aware" across your federated environments.
Poyraz-K8s, son derece hassas ve çok boyutlu güvenlik politikaları uygulamak için güçlü Casbin Motoru (Casbin Engine) kullanır. Standart Kubernetes RBAC sisteminin aksine, Poyraz RBAC, federatif ortamlarınızda tamamen "Küme Duyarlıdır (Cluster-Aware)".
The 5-Tuple Policy Pattern
5 Boyutlu Politika Modeli
[ subject, domain(cluster_uid), namespace, object, action ]. Every user action must satisfy these 5 dynamic conditions.
[ özne, domain(küme_uid), namespace, nesne, eylem ]. Her kullanıcı eylemi bu 5 dinamik koşulu sağlamalıdır.
Cluster (Domain) Isolation
Küme İzolasyonu
If User A has "Admin" rights on Cluster X, they are still fundamentally blocked from even viewing Cluster Y, unless a specific Domain binding exists.
Eğer Kullanıcı A'nın X Kümesinde "Admin" hakları varsa bile, Y Kümesini görüntülemesi (özel bir Domain bağlamı yoksa) temelden engellenir.
Wildcard Engine
Joker Karakter Motoru
Specific namespaces can be restricted via RegEx patterns (e.g. prod-* vs dev-*). Allowing devs access exclusively to testing namespaces.
Belirli ad alanları (namespaces) RegEx pattern'leri ile sınırlandırılabilir (örneğin prod-* ile dev-* ayrımı). Geliştiricilere sadece test alanlarında yetki verilebilir.
Casbin Specifications
Casbin Spesifikasyonları
| Policy Example | p, viewer-role, clstr-8f4b, *, page:Terminal, accessThe Viewer Role, ONLY inside Cluster "clstr-8f4b", in any Namespace (*), can access the Terminal page. Viewer (Görüntüleyici) Rolü, SADECE "clstr-8f4b" Kümesinde, herhangi bir isim alanında (*), Terminal sayfasına erişebilir. |
| Role Binding | g, john.doe, viewer-role, clstr-8f4bJohn Doe is securely linked to the Viewer Role, tied exclusively to that Cluster UID. John Doe, Viewer Rolüne bağlanmış ve sadece o Küme UID'sine özel yetkilendirilmiştir. |
Superadmin Bypass
Süper-Admin Otoritesi
Superadmin flags bypass all Casbin routing. A user mapped to the SUPERADMIN global domain * has unfiltered access to every attached Kubeconfig and UI metric.
Superadmin yetkisi tüm Casbin denetimlerini atlatır (bypass). Küresel domain (*) üzerine eşlenmiş SUPERADMIN her Kubeconfig ve metrik arayüzüne filtresiz erişime sahiptir.
Multi-Tenancy Guard
Çoklu Kiracı (Multi-Tenancy) Koruması
The Backend prevents memory-leaks of Kubeconfigs. A user session executing a deploy only has the specific cluster authorization injected right before task initiation.
Backend sistemi Kubeconfig sızıntılarını engeller. Deploy (dağıtım) gerçekleştiren bir kullanıcı oturumuna, görev başlamadan saniyeler önce sadece kendisinin yetkili olduğu küme konfigürasyonu (Kubeconfig) enjekte edilir.