- Sort Score
- Result 10 results
- Languages All
Results 1 - 10 of 197 for privilege (0.27 sec)
-
manifests/charts/istio-cni/values.yaml
# Note this gives the DaemonSet a relatively high privilege, as modifying pod metadata/status can have wider impacts. labelPods: false # deletePods will delete any broken pod. These will then be rescheduled, hopefully onto a node that is fully ready. # Note this gives the DaemonSet a relatively high privilege, as it can delete any Pod. deletePods: false
Registered: Fri Jun 14 15:00:06 UTC 2024 - Last Modified: Tue May 21 18:32:01 UTC 2024 - 5.2K bytes - Viewed (0) -
releasenotes/notes/remove-anyuid-openshift.yaml
kind: feature area: installation docs: - 'https://istio.io/latest/docs/setup/platform-setup/openshift/' releaseNotes: - |
Registered: Fri Jun 14 15:00:06 UTC 2024 - Last Modified: Fri Aug 25 19:10:42 UTC 2023 - 297 bytes - Viewed (0) -
releasenotes/notes/bookinfo-openshift.yaml
kind: feature area: documentation docs: - 'https://istio.io/latest/docs/setup/platform-setup/openshift/' releaseNotes: - |
Registered: Fri Jun 14 15:00:06 UTC 2024 - Last Modified: Mon May 15 13:53:27 UTC 2023 - 250 bytes - Viewed (0) -
cni/pkg/util/podutil.go
Patch( context.Background(), pod.Name, types.MergePatchType, annotationPatch, metav1.PatchOptions{}, // Both "pods" and "pods/status" can mutate the metadata. However, pods/status is lower privilege, so we use that instead. "status", ) return err } func AnnotateUnenrollPod(client kubernetes.Interface, pod *metav1.ObjectMeta) error {
Registered: Fri Jun 14 15:00:06 UTC 2024 - Last Modified: Fri May 31 17:18:11 UTC 2024 - 4.4K bytes - Viewed (0) -
src/runtime/security_test.go
// setuid binaries from executing because of the missing g+rx, so we need to set the parent // directory to better permissions before anything else. We created this directory, so we // shouldn't need to do any privilege trickery. if err := privesc("chmod", "0777", filepath.Dir(bin)); err != nil { t.Skipf("unable to set permissions on %q, likely no passwordless sudo/su: %s", filepath.Dir(bin), err) }
Registered: Wed Jun 12 16:32:35 UTC 2024 - Last Modified: Tue Jun 13 18:10:14 UTC 2023 - 4.1K bytes - Viewed (0) -
tools/istio-iptables/pkg/log/nflog.go
"istio.io/istio/pkg/env" "istio.io/istio/pkg/log" ) var TraceLoggingEnabled = env.Register( "IPTABLES_TRACE_LOGGING", false, "When enable, all iptables actions will be logged. "+ "This requires NET_ADMIN privilege and has noisy logs; as a result, this is intended for debugging only").Get() var iptablesTrace = log.RegisterScope("iptables", "trace logs for iptables") // ReadNFLOGSocket reads from the nflog socket, sending output to logs.
Registered: Fri Jun 14 15:00:06 UTC 2024 - Last Modified: Thu Jun 06 15:59:40 UTC 2024 - 2.8K bytes - Viewed (0) -
pkg/registry/rbac/role/policybased/storage.go
See the License for the specific language governing permissions and limitations under the License. */ // Package policybased implements a standard storage for Role that prevents privilege escalation. package policybased import ( "context" "k8s.io/apimachinery/pkg/api/errors" metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" "k8s.io/apimachinery/pkg/runtime"
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Fri Nov 18 10:11:16 UTC 2022 - 3.9K bytes - Viewed (0) -
pkg/registry/rbac/clusterrole/policybased/storage.go
See the License for the specific language governing permissions and limitations under the License. */ // Package policybased implements a standard storage for ClusterRole that prevents privilege escalation. package policybased import ( "context" "errors" apierrors "k8s.io/apimachinery/pkg/api/errors" metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" "k8s.io/apimachinery/pkg/runtime"
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Fri Nov 18 10:11:16 UTC 2022 - 5.2K bytes - Viewed (0) -
pkg/registry/rbac/rolebinding/policybased/storage.go
See the License for the specific language governing permissions and limitations under the License. */ // Package policybased implements a standard storage for RoleBinding that prevents privilege escalation. package policybased import ( "context" rbacv1 "k8s.io/api/rbac/v1" "k8s.io/apimachinery/pkg/api/errors" metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" "k8s.io/apimachinery/pkg/runtime"
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Fri Nov 18 10:11:16 UTC 2022 - 5.5K bytes - Viewed (0) -
pkg/registry/rbac/clusterrolebinding/policybased/storage.go
See the License for the specific language governing permissions and limitations under the License. */ // Package policybased implements a standard storage for ClusterRoleBinding that prevents privilege escalation. package policybased import ( "context" rbacv1 "k8s.io/api/rbac/v1" "k8s.io/apimachinery/pkg/api/errors" metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" "k8s.io/apimachinery/pkg/runtime"
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Fri Nov 18 10:11:16 UTC 2022 - 4.9K bytes - Viewed (0)