Skip to content

k8s: selector/namespace-based zone assignment with an RBAC story #75

@yairfalse

Description

@yairfalse

Annotation-only assignment means anyone with pod-patch rights picks their own zone — multi-tenant non-starter. Add SyvaZonePolicy selector-based assignment and/or namespace defaults, document the trust model and required RBAC boundaries.

Part of the v0.4 roadmap.

🤖 Generated with Claude Code

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions