I want to restrict the read & write access of secrets only to the users with ADMIN roles in openshift. If a user is a normal user, he can access everything except the secrets(he can't reveal the secrets and edit also). Is there any way to do that? Thank You!
Is there a way to give read & write access of secrets only to ADMIN user in openshift?
1.1k Views Asked by Sukanya Mallick At
1
There are 1 best solutions below
Related Questions in OPENSHIFT
- OpenShift Pyramid logging to file
- com.mongodb.MongoException: not authorized for insert on myworld.Users
- Openshift context path
- error while establishing connection with node.js server OpenShift
- Cannot port forward for app
- OpenShift - Tomcat 7 (JBoss EWS 2.0) + PostgreSQL 9.2 + Hibernate 4.3.5
- running node.js sails app on openshift
- Can't get Pandas to install with OpenShift
- Cartridge Python2.7 on OPenshift
- OpenShift Requirements.txt Pip error
- OpenShift PHP Image Asset Giving 500 Error
- Codeigniter on OpenShift is redirecting to 404 error page
- Why mongodb is reset after push to openshift
- Openshift - trigger Jenkins build on git push
- Openshift redirect to https using flask-base example
Related Questions in OPENSHIFT-3
- Error occurred while starting the build in Openshift 3
- How to know OpenShift 3 fetched latest source code?
- Is there a way to give read & write access of secrets only to ADMIN user in openshift?
- Labelling Openshift Build transient pods
- How to extend the validity of openshift kublet-server, kublet-client certificates of all the nodes?
- Unable to redeploy the certificates post-expiry in openshift 3.11
- openshift 3.11 oc command : error: Error loading config file ".kube/config": yaml: line 11: could not find expected ':'
- How to install .NetCore dotnet (not MSBuid plugin) to Jenkins
- Openshift 3.11: controller-manager crashloopbackoff - unable to retrieve the complete list of server APIs: servicecatalog.k8s.io/v1beta
- K8s/Openshift - does the replication controller care about exit status of pod/containers?
- IBM MQ doesn't run as mqm on Openshift 4
- How to destroy pod with status "Unknown" in openshift?
- Openshift container as root user
- How to run a job in openshift to schedule a particular script?
- How to expose containerized asp.net core web api app in openSHIFT ORIGIN
Trending Questions
- UIImageView Frame Doesn't Reflect Constraints
- Is it possible to use adb commands to click on a view by finding its ID?
- How to create a new web character symbol recognizable by html/javascript?
- Why isn't my CSS3 animation smooth in Google Chrome (but very smooth on other browsers)?
- Heap Gives Page Fault
- Connect ffmpeg to Visual Studio 2008
- Both Object- and ValueAnimator jumps when Duration is set above API LvL 24
- How to avoid default initialization of objects in std::vector?
- second argument of the command line arguments in a format other than char** argv or char* argv[]
- How to improve efficiency of algorithm which generates next lexicographic permutation?
- Navigating to the another actvity app getting crash in android
- How to read the particular message format in android and store in sqlite database?
- Resetting inventory status after order is cancelled
- Efficiently compute powers of X in SSE/AVX
- Insert into an external database using ajax and php : POST 500 (Internal Server Error)
Popular Questions
- How do I undo the most recent local commits in Git?
- How can I remove a specific item from an array in JavaScript?
- How do I delete a Git branch locally and remotely?
- Find all files containing a specific text (string) on Linux?
- How do I revert a Git repository to a previous commit?
- How do I create an HTML button that acts like a link?
- How do I check out a remote Git branch?
- How do I force "git pull" to overwrite local files?
- How do I list all files of a directory?
- How to check whether a string contains a substring in JavaScript?
- How do I redirect to another webpage?
- How can I iterate over rows in a Pandas DataFrame?
- How do I convert a String to an int in Java?
- Does Python have a string 'contains' substring method?
- How do I check if a string contains a specific word?
You could try to create your own roles to apply to everyone who is not an admin or just edit the non-admin roles removing access to secrets.
Here the guide to make your own role.
For example your role can already be like:
and you could remove the secrets line under resources:
For example: