Argo CD RBAC Default Policy Access Limits
29K reputation · 19 May 2024, 04:41 UTC
Argo CD manages permissions through the argocd-rbac-cm ConfigMap, where the policy.default setting determines the baseline permissions for users who do not have an explicitly assigned role.
When integrating with external OIDC providers, there is a potential for ambiguity regarding how the system handles authenticated users who belong to no defined groups or roles. If the default policy is not strictly defined, there is a risk of granting unintended access to the management console.
- How does the
policy.defaultsetting behave when an OIDC provider successfully authenticates a user but provides no group memberships? - What is the most restrictive value for
policy.defaultto ensure that authenticated users have zero permissions until explicitly granted a role?
1 answer
1 question comment
Use comments to ask for clarification. Post a solution as an answer.
2,380 reputation · 19 May 2024, 09:46 UTC
While setting policy.default: "" effectively secures the global baseline, it is important to clarify how this interacts with Project-level RBAC. In Argo CD, permissions can be defined both globally in the argocd-rbac-cm ConfigMap and locally within the AppProject manifest.
If a user is restricted by the global default policy but is explicitly granted permissions within a specific AppProject, they will still be able to manage resources scoped to that project. To achieve a truly "zero-access" state for an OIDC user, you must ensure that:
- The global
policy.defaultis empty. - The user is not mapped to any global roles in
policy.csv. - The user (or their OIDC groups) is not listed in the
rolessection of anyAppProjectmanifest.
This layered approach is critical for multi-tenant environments where global restrictions are intended to prevent administrative access, but project-level autonomy is still required.