Tenancy¶
Attune runs once per cluster and resizes pods. The people who create
AttunePolicy objects are not the same people who install the operator.
This page says what each of them can make the operator do.
Trust levels¶
Cluster level is the operator install and cluster AttuneDefaults.
- Helm values and operator flags choose credentials: the Prometheus ServiceAccount token, the operator bearer Secret, the Datadog API key Secret, and the SigV4 allowlists.
- Cluster
AttuneDefaultschooses the metrics address, a SigV4 role, a CloudWatch role, a VPA in any namespace, and SLO guardrails. - Those guardrails keep the operator credentials and are not rewritten.
Namespace level is AttuneNamespaceDefaults and AttunePolicy in that
namespace.
- A policy resizes workloads in its own namespace.
- A Secret reference is a name in that namespace. The name cannot contain
/. When the validating webhook is on, the admission user must be allowed togetthat Secret. - A Prometheus address, Datadog block, or CloudWatch block set on the
policy or on
AttuneNamespaceDefaultsdoes not receive operator Prometheus or Datadog credentials. metricsSource.vpa.namespacemust be empty or that same namespace. A VPA namespace inherited only from clusterAttuneDefaultsis still read.sigv4.roleArnandcloudwatch.roleArnmust match--sigv4-allowed-role-arns.sigv4with noroleArnsigns with the operator identity and the workspace host must match--sigv4-allowed-workspace-hosts. Both lists are empty until you set them, so a namespace object cannot use them until then. ClusterAttuneDefaultsis not filtered.- When a namespaced policy assumes a role, STS receives
ExternalIdattune:<namespace>. - SLO guardrails written on the policy or on
AttuneNamespaceDefaultsare tenant guardrails. When they would run with operator Prometheus credentials, Attune addsnamespace="<policy namespace>"to every vector selector. A selector that already requires a different namespace is not sent, and it does not extend safety observation or canary promotion. Set--slo-guardrail-enforce-namespace=falseto skip those guardrails instead. The breach event does not include the numeric value.
Datadog and CloudWatch do not evaluate SLO guardrails. They also do not extend canary promotion or safety observation for a guardrail window.
Webhooks off¶
--enable-webhooks=false removes admission. That includes the Secret
SubjectAccessReview and the rejection of a cross-namespace VPA, a
non-allowlisted role, and a non-allowlisted SigV4 host.
Reconcile still refuses those three. A tenant guardrail that would use operator Prometheus credentials is still scoped, or skipped when namespace enforcement is off.
Who should get which CRD¶
| CRD | Who should create it |
|---|---|
AttuneDefaults |
Cluster admins |
AttuneNamespaceDefaults |
Admins of that namespace |
AttunePolicy |
The team that owns the workloads in that namespace |
The chart ships <fullname>-policy-viewer and <fullname>-policy-editor
ClusterRoles. helm install attune names them attune-policy-viewer
and attune-policy-editor. A release name that does not contain
attune uses <release>-attune-policy-editor. They do not aggregate
into view, edit, or admin unless rbac.aggregateToView or
rbac.aggregateToEdit is true. Bind the editor role to the teams that
should create policies. Do not bind AttuneDefaults the same way.
Kustomize config/default sets namePrefix: attune-. The role
manifests are named policy-viewer and policy-editor, so the install
creates attune-policy-viewer and attune-policy-editor. Bind those
names. The roles have no aggregate labels, so a default install does
not grant every edit user AttunePolicy create.