SIGN IN SIGN UP

feat(core): add scoped authorization for catalog resources (#2710)

## Summary

- Add policy-neutral collection scopes while keeping the default OSS
installation open.
- Enforce scoped access for `AgentTemplate`, `Harness`, and
`ModelConfig` using trusted Kubernetes metadata.
- Filter list responses server-side while keeping create, update, and
delete authorization authoritative at execution time.
- Keep UI-only authorization hints out of the catalog protobuf API.

Backend half of #2683. The UI may display actions a caller cannot
perform; denied requests return `PermissionDenied`.

## Breaking change

`app.Options.Authorizer` moves from `auth.Authorizer` to
`auth.CollectionAuthorizer`. It is the documented authorization
extension point, so an embedder supplying a `Check`-only authorizer must
also provide collection scopes. The default OSS behavior remains
unrestricted.

## Testing

```bash
make -C go lint
(cd go && GOCACHE=/tmp/kagent-scoped-auth-go-cache go test -short ./...)
(cd go && GOCACHE=/tmp/kagent-scoped-auth-go-cache go test ./core/pkg/auth ./core/pkg/app ./core/internal/httpserver/auth ./core/internal/service/model ./core/internal/service/prompttemplate ./core/internal/service/system ./core/internal/grpcserver ./core/internal/mcp)
(cd ui && ./node_modules/.bin/tsc --noEmit)
```

The full Go E2E suite also passed against the local Kind cluster.

---------

Signed-off-by: Cody Hartsook <cody.hartsook@solo.io>
C
Cody Hartsook committed
00a53a3aea932123957dc67691cdb13300cdd2d9
Parent: cc06dd1
Committed by GitHub <noreply@github.com> on 9/16/2026, 12:30:36 PM