- Sort Score
- Result 10 results
- Languages All
Results 1 - 10 of 18 for GetSubresource (0.21 sec)
-
plugin/pkg/auth/authorizer/node/node_authorizer.go
return r.authorizeReadNamespacedObject(nodeName, secretVertexType, attrs) case configMapResource: return r.authorizeReadNamespacedObject(nodeName, configMapVertexType, attrs) case pvcResource: if attrs.GetSubresource() == "status" { return r.authorizeStatusUpdate(nodeName, pvcVertexType, attrs) } return r.authorizeGet(nodeName, pvcVertexType, attrs) case pvResource:
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Thu Mar 07 21:22:55 UTC 2024 - 16K bytes - Viewed (0) -
plugin/pkg/admission/gc/gc_admission.go
// // if the request is in the whitelist, we skip mutation checks for this resource. if a.isWhiteListed(attributes.GetResource().GroupResource(), attributes.GetSubresource()) { return nil } // if we aren't changing owner references, then the edit is always allowed if !isChangingOwnerReference(attributes.GetObject(), attributes.GetOldObject()) { return nil }
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Tue Sep 05 02:24:38 UTC 2023 - 10.3K bytes - Viewed (0) -
plugin/pkg/admission/gc/gc_admission_test.go
username := a.GetUser().GetName() if username == "non-deleter" { if a.GetVerb() == "delete" { return authorizer.DecisionNoOpinion, "", nil } if a.GetVerb() == "update" && a.GetSubresource() == "finalizers" { return authorizer.DecisionNoOpinion, "", nil } if a.GetAPIGroup() == "*" && a.GetResource() == "*" { // this user does not have full rights return authorizer.DecisionNoOpinion, "", nil }
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Mon Apr 29 21:28:42 UTC 2024 - 24.5K bytes - Viewed (0) -
plugin/pkg/admission/serviceaccount/admission.go
return admission.NewForbidden(a, err) } } return nil } func shouldIgnore(a admission.Attributes) bool { if a.GetResource().GroupResource() != api.Resource("pods") || (a.GetSubresource() != "" && a.GetSubresource() != "ephemeralcontainers") { return true } obj := a.GetObject() if obj == nil { return true } _, ok := obj.(*api.Pod) if !ok { return true }
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Fri Apr 12 17:49:30 UTC 2024 - 18.6K bytes - Viewed (0) -
plugin/pkg/admission/noderestriction/admission.go
case podResource: switch a.GetSubresource() { case "": return p.admitPod(nodeName, a) case "status": return p.admitPodStatus(nodeName, a) case "eviction": return p.admitPodEviction(nodeName, a) default: return admission.NewForbidden(a, fmt.Errorf("unexpected pod subresource %q, only 'status' and 'eviction' are allowed", a.GetSubresource())) } case nodeResource:
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Thu Mar 07 21:22:55 UTC 2024 - 23.6K bytes - Viewed (0) -
staging/src/k8s.io/apiserver/pkg/admission/plugin/cel/filter.go
gvk := equivalentKind gvr := equivalentGVR subresource := attr.GetSubresource() requestGVK := attr.GetKind() requestGVR := attr.GetResource() requestSubResource := attr.GetSubresource() aUserInfo := attr.GetUserInfo() var userInfo authenticationv1.UserInfo if aUserInfo != nil { userInfo = authenticationv1.UserInfo{
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Mon Jul 24 14:46:11 UTC 2023 - 12.1K bytes - Viewed (0) -
staging/src/k8s.io/apiserver/pkg/cel/library/authz.go
GetNamespace() string // GetResource is the name of the resource being requested. This is not the kind. For example: pods GetResource() schema.GroupVersionResource // GetSubresource is the name of the subresource being requested. This is a different resource, scoped to the parent resource, but it may have a different kind.
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Wed Aug 23 21:31:27 UTC 2023 - 21.1K bytes - Viewed (0) -
pkg/controller/servicecidrs/servicecidrs_controller_test.go
t.Errorf("Expected action %d resource to be %s, got %s", i, resource, action.GetResource().Resource) } subresource := expected[i][2] if action.GetSubresource() != subresource { t.Errorf("Expected action %d subresource to be %s, got %s", i, subresource, action.GetSubresource()) } } } func TestController_canDeleteCIDR(t *testing.T) { tests := []struct { name string
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Mon Feb 26 06:51:56 UTC 2024 - 22K bytes - Viewed (0) -
staging/src/k8s.io/apiserver/plugin/pkg/authorizer/webhook/webhook.go
Namespace: attr.GetNamespace(), Verb: attr.GetVerb(), Group: attr.GetAPIGroup(), Version: attr.GetAPIVersion(), Resource: attr.GetResource(), Subresource: attr.GetSubresource(), Name: attr.GetName(), } } else { r.Spec.NonResourceAttributes = &authorizationv1.NonResourceAttributes{ Path: attr.GetPath(), Verb: attr.GetVerb(), } }
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Mon Mar 04 19:01:15 UTC 2024 - 18.4K bytes - Viewed (0) -
pkg/kubelet/server/server.go
msg := fmt.Sprintf("Authorization error (user=%s, verb=%s, resource=%s, subresource=%s)", attrs.GetUser().GetName(), attrs.GetVerb(), attrs.GetResource(), attrs.GetSubresource()) resp.WriteErrorString(http.StatusInternalServerError, msg) return } if decision != authorizer.DecisionAllow {
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Tue Jun 04 06:25:43 UTC 2024 - 40.1K bytes - Viewed (0)