This message was deleted.
# general
s
This message was deleted.
y
In your case (token/pulsar authorization), subject is JWT token term and role is pulsar authorization term. It is authorization plugin’s job to define how to translate token subject to pulsar role.
the default one is just 1:1 mapping. subject = role.
j
och I see, thank you. In that case should token generated for subject "testsubject" be defined in proxy config as proxyroles: testsubject ? or should that work regardless as long as there's proper permission set at namespace level ? I think I've tested both though, just trying to figure out which part I might have misconfigured
y
proxy config just set the “init” admin role. to setup different roles for tenant/namespace/topic/function, you can use pulsarctl/pulsar admin to grant non-admin roles (consume/produce/function….). Those roles are recorded in metadata, not in config.
j
thank you 🙂
would you might commenting on the following too ?
Copy code
Illegal combination of role [proxyadmin] and originalPrincipal [jacek]: cannot specify originalPrincipal when connecting without valid proxy role.
While this seems like obvious mismatch I am having hard time understanding why proxy wouldn't forward token (subject=jacek) to a broker for authorization. Proxy is set to forwardAuthorizationCredentials:true, I didn't specify proxyroles - which I assume means it uses proxyadmin for communication between proxy and brokers.
y
what’s the auth.superUsers.proxy in your helmchart value?
j
I think we were able to get it, currently we have adminproxy, that's listed in proxyroles on broker conf and it kinda works while interacting as a different subject with related topics
👍 1