Skip to content

Adapter: unify RBAC for Side Effecting Functions#35220

Draft
DAlperin wants to merge 1 commit intoMaterializeInc:mainfrom
DAlperin:dov/unify-rbac-side-effecting-function
Draft

Adapter: unify RBAC for Side Effecting Functions#35220
DAlperin wants to merge 1 commit intoMaterializeInc:mainfrom
DAlperin:dov/unify-rbac-side-effecting-function

Conversation

@DAlperin
Copy link
Member

@DAlperin DAlperin commented Feb 25, 2026

During an incident I tried to kill some backends with mz_system and I couldn't. This was because the usually RBAC bypass doesn't work for the special impl in the coord for side effect functions. I'd prefer to unify this where possible and feel it's worth paying an extra coord hop is worth it.

@github-actions
Copy link

Thanks for opening this PR! Here are a few tips to help make the review process smooth for everyone.

PR title guidelines

  • Use imperative mood: "Fix X" not "Fixed X" or "Fixes X"
  • Be specific: "Fix panic in catalog sync when controller restarts" not "Fix bug" or "Update catalog code"
  • Prefix with area if helpful: compute: , storage: , adapter: , sql:

Pre-merge checklist

  • The PR title is descriptive and will make sense in the git log.
  • This PR has adequate test coverage / QA involvement has been duly considered. (trigger-ci for additional test/nightly runs)
  • If this PR includes major user-facing behavior changes, I have pinged the relevant PM to schedule a changelog post.
  • This PR has an associated up-to-date design doc, is a design doc (template), or is sufficiently small to not require a design.
  • If this PR evolves an existing $T ⇔ Proto$T mapping (possibly in a backwards-incompatible way), then it is tagged with a T-proto label.
  • If this PR will require changes to cloud orchestration or tests, there is a companion cloud PR to account for those changes that is tagged with the release-blocker label (example).

@DAlperin DAlperin force-pushed the dov/unify-rbac-side-effecting-function branch from 889e2d6 to 1f82600 Compare February 25, 2026 21:42
During an incident I tried to kill some backends with mz_system and I
couldn't. This was because the usually RBAC bypass doesn't work for the
special impl in the coord for side effect functions. I'd prefer to unify
this where possible and feel it's worth paying an extra coord hop is
worth it.
@DAlperin DAlperin force-pushed the dov/unify-rbac-side-effecting-function branch from 1f82600 to 66b07dd Compare February 25, 2026 22:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant