E537 chore(multicluster): add missing Server/AuthorizationPolicy resources by alpeb · Pull Request #14992 · linkerd/linkerd2 · GitHub
[go: up one dir, main page]

Skip to content

chore(multicluster): add missing Server/AuthorizationPolicy resources#14992

Open
alpeb wants to merge 2 commits intomainfrom
alpeb/mc-server
Open

chore(multicluster): add missing Server/AuthorizationPolicy resources#14992
alpeb wants to merge 2 commits intomainfrom
alpeb/mc-server

Conversation

@alpeb
Copy link
Member
@alpeb alpeb commented Mar 4, 2026

Following the change in mirror controllers (#13768) and the port names renaming (#14111) we didn't appropriately update the authorization policies that the linkerd-multicluster chart ships with, that grants access to viz' prometheus SA.

Additionally, #13269 introduced a local service mirror controller that wasn't accounted for in these policies either.

Finally, the linkerd-admin port in the linkerd-multicluster namespace didn't have any authorizations associated.

This was preventing scraping these controllers (both the controllers main container and the linkerd-admin metrics) when having restricted default inbound policies, either by viz' prometheus, or other prometheus instances relying on these Servers.

Following the change in mirror controllers (#13768) and the port names
renaming (#14111) we didn't appropriately update the authorization
policies that the linkerd-multicluster chart ships with, that grants
access to viz' prometheus SA.

Additionally, #13269 introduced a local service mirror controller that
wasn't accounted for in these policies either.

This was preventing scraping these controllers when having restricted
default inbound policies, either by viz' prometheus, or other prometheus
instances relying on these Servers.
@alpeb alpeb requested a review from a team as a code owner March 4, 2026 22:55
@alpeb alpeb requested a review from zaharidichev March 5, 2026 16:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

0