feat(operator): migrate from kube-rbac-proxy to built-in controller-runtime protection #41
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Resolves #35
This drops the kube-rbac-proxy sidecar in favor of controller-runtime's native WithAuthenticationAndAuthorization filter, introduced in v0.18+.This change is required because the gcr.io/kubebuilder/kube-rbac-proxy image has been deprecated and is scheduled for removal: kubernetes-sigs/kubebuilder#3907
I choose not to upgrade to the latest kubebuilder release because this requires re-scaffolding and reintegrating our custom code (which is fairly extensive). Instead I followed the steps in the FAQ "How can I manually change my project to switch to Controller-Runtime's built-in auth protection?".
Testing