feat(core): add scoped authorization for catalog resources (#2710)
## Summary - Add policy-neutral collection scopes while keeping the default OSS installation open. - Enforce scoped access for `AgentTemplate`, `Harness`, and `ModelConfig` using trusted Kubernetes metadata. - Filter list responses server-side while keeping create, update, and delete authorization authoritative at execution time. - Keep UI-only authorization hints out of the catalog protobuf API. Backend half of #2683. The UI may display actions a caller cannot perform; denied requests return `PermissionDenied`. ## Breaking change `app.Options.Authorizer` moves from `auth.Authorizer` to `auth.CollectionAuthorizer`. It is the documented authorization extension point, so an embedder supplying a `Check`-only authorizer must also provide collection scopes. The default OSS behavior remains unrestricted. ## Testing ```bash make -C go lint (cd go && GOCACHE=/tmp/kagent-scoped-auth-go-cache go test -short ./...) (cd go && GOCACHE=/tmp/kagent-scoped-auth-go-cache go test ./core/pkg/auth ./core/pkg/app ./core/internal/httpserver/auth ./core/internal/service/model ./core/internal/service/prompttemplate ./core/internal/service/system ./core/internal/grpcserver ./core/internal/mcp) (cd ui && ./node_modules/.bin/tsc --noEmit) ``` The full Go E2E suite also passed against the local Kind cluster. --------- Signed-off-by: Cody Hartsook <cody.hartsook@solo.io>
C
Cody Hartsook committed
00a53a3aea932123957dc67691cdb13300cdd2d9
Parent: cc06dd1
Committed by GitHub <noreply@github.com>
on 9/16/2026, 12:30:36 PM