youtube image
From YouTube: CF on K8s WG Forum 16th Nov 2021

Description

Recording from the CF on K8s Working Group Forum call held on 16th November 2021.


Topics
[TD] HNC propagation woes making it difficult to stage (and probably run) apps
- https://github.com/cloudfoundry/cf-k8s-controllers/issues/243
Service accounts / Secrets don’t propagate. This is an issue with Kpack.
Disable SA propagation and have shim create SAs?
Lends weight toward CRD abstraction for Orgs/Spaces.
HNC webhook is also aggressive https://github.com/kubernetes-sigs/multi-tenancy/blob/master/incubator/hnc/config/webhook/manifests.yaml#L95-L116
Needed to monitor everything under nested namespaces
[GC] Binding Service Accounts
Users vs Service Accounts -- perhaps add a defaulted field/parameter on requests that would allow end users to create service accounts. This should maintain backwards compatibility with current CF API.
Create Role https://v3-apidocs.cloudfoundry.org/version/3.110.0/index.html#create-a-role