Search Options

Results per page
Sort
Preferred Languages
Advance

Results 1 - 10 of 82 for serviceAccountToken (0.37 sec)

  1. pkg/controller/serviceaccount/tokens_controller_test.go

    }
    
    // serviceAccountTokenSecretWithoutTokenData returns an existing ServiceAccountToken secret that lacks token data
    func serviceAccountTokenSecretWithoutTokenData() *v1.Secret {
    	secret := serviceAccountTokenSecret()
    	delete(secret.Data, v1.ServiceAccountTokenKey)
    	return secret
    }
    
    // serviceAccountTokenSecretWithoutCAData returns an existing ServiceAccountToken secret that lacks ca data
    Registered: Sat Jun 15 01:39:40 UTC 2024
    - Last Modified: Fri Apr 14 00:05:53 UTC 2023
    - 21.5K bytes
    - Viewed (0)
  2. plugin/pkg/admission/serviceaccount/admission.go

    		}
    		for _, v := range pod.Spec.Volumes {
    			if proj := v.Projected; proj != nil {
    				for _, projSource := range proj.Sources {
    					if projSource.ServiceAccountToken != nil {
    						return admission.NewForbidden(a, fmt.Errorf("a mirror pod may not use ServiceAccountToken volume projections"))
    					}
    				}
    			}
    		}
    		return nil
    	}
    
    	// Require container pods to have service accounts
    Registered: Sat Jun 15 01:39:40 UTC 2024
    - Last Modified: Fri Apr 12 17:49:30 UTC 2024
    - 18.6K bytes
    - Viewed (0)
  3. pkg/apis/extensions/v1beta1/zz_generated.defaults.go

    						c := &b.DownwardAPI.Items[k]
    						if c.FieldRef != nil {
    							v1.SetDefaults_ObjectFieldSelector(c.FieldRef)
    						}
    					}
    				}
    				if b.ServiceAccountToken != nil {
    					v1.SetDefaults_ServiceAccountTokenProjection(b.ServiceAccountToken)
    				}
    			}
    		}
    		if a.VolumeSource.ScaleIO != nil {
    			v1.SetDefaults_ScaleIOVolumeSource(a.VolumeSource.ScaleIO)
    		}
    		if a.VolumeSource.Ephemeral != nil {
    Registered: Sat Jun 15 01:39:40 UTC 2024
    - Last Modified: Fri Jan 06 09:07:02 UTC 2023
    - 31.2K bytes
    - Viewed (0)
  4. pkg/apis/batch/v1beta1/zz_generated.defaults.go

    						c := &b.DownwardAPI.Items[k]
    						if c.FieldRef != nil {
    							v1.SetDefaults_ObjectFieldSelector(c.FieldRef)
    						}
    					}
    				}
    				if b.ServiceAccountToken != nil {
    					v1.SetDefaults_ServiceAccountTokenProjection(b.ServiceAccountToken)
    				}
    			}
    		}
    		if a.VolumeSource.ScaleIO != nil {
    			v1.SetDefaults_ScaleIOVolumeSource(a.VolumeSource.ScaleIO)
    		}
    		if a.VolumeSource.Ephemeral != nil {
    Registered: Sat Jun 15 01:39:40 UTC 2024
    - Last Modified: Wed Mar 01 20:39:47 UTC 2023
    - 10.8K bytes
    - Viewed (0)
  5. pkg/apis/core/v1/zz_generated.defaults.go

    						c := &b.DownwardAPI.Items[k]
    						if c.FieldRef != nil {
    							SetDefaults_ObjectFieldSelector(c.FieldRef)
    						}
    					}
    				}
    				if b.ServiceAccountToken != nil {
    					SetDefaults_ServiceAccountTokenProjection(b.ServiceAccountToken)
    				}
    			}
    		}
    		if a.VolumeSource.ScaleIO != nil {
    			SetDefaults_ScaleIOVolumeSource(a.VolumeSource.ScaleIO)
    		}
    		if a.VolumeSource.Ephemeral != nil {
    Registered: Sat Jun 15 01:39:40 UTC 2024
    - Last Modified: Fri Mar 10 14:49:26 UTC 2023
    - 37.8K bytes
    - Viewed (0)
  6. pkg/kube/inject/testdata/inject/list.yaml.injected

                    fieldPath: metadata.annotations
                  path: annotations
              name: istio-podinfo
            - name: istio-token
              projected:
                sources:
                - serviceAccountToken:
                    audience: istio-ca
                    expirationSeconds: 43200
                    path: istio-token
            - configMap:
                name: istio-ca-root-cert
              name: istiod-ca-cert
    Registered: Fri Jun 14 15:00:06 UTC 2024
    - Last Modified: Tue Feb 27 16:55:16 UTC 2024
    - 14.2K bytes
    - Viewed (0)
  7. pkg/kube/inject/testdata/inject/hello-multi.yaml.injected

              - fieldRef:
                  fieldPath: metadata.annotations
                path: annotations
            name: istio-podinfo
          - name: istio-token
            projected:
              sources:
              - serviceAccountToken:
                  audience: istio-ca
                  expirationSeconds: 43200
                  path: istio-token
          - configMap:
              name: istio-ca-root-cert
            name: istiod-ca-cert
    status: {}
    Registered: Fri Jun 14 15:00:06 UTC 2024
    - Last Modified: Tue Feb 27 16:55:16 UTC 2024
    - 13.2K bytes
    - Viewed (0)
  8. operator/cmd/mesh/testdata/manifest-generate/output/ingressgateway_k8s_settings.golden.yaml

            name: podinfo
          - emptyDir: {}
            name: istio-envoy
          - emptyDir: {}
            name: istio-data
          - name: istio-token
            projected:
              sources:
              - serviceAccountToken:
                  audience: istio-ca
                  expirationSeconds: 43200
                  path: istio-token
          - configMap:
              name: istio
              optional: true
            name: config-volume
    Registered: Fri Jun 14 15:00:06 UTC 2024
    - Last Modified: Fri Dec 01 22:07:45 UTC 2023
    - 14.3K bytes
    - Viewed (0)
  9. pkg/volume/projected/projected_test.go

    			testNamespace := "test_projected_namespace"
    			source := makeProjection(tc.name, tc.defaultMode, "serviceAccountToken")
    			source.Sources[0].ServiceAccountToken.Audience = tc.audience
    			source.Sources[0].ServiceAccountToken.ExpirationSeconds = tc.expiration
    			source.Sources[0].ServiceAccountToken.Path = tc.path
    
    			testPodUID := types.UID("test_pod_uid")
    			pod := &v1.Pod{
    Registered: Sat Jun 15 01:39:40 UTC 2024
    - Last Modified: Fri Nov 03 18:40:48 UTC 2023
    - 40.5K bytes
    - Viewed (0)
  10. pkg/volume/projected/projected.go

    			if err != nil {
    				errlist = append(errlist, err)
    				continue
    			}
    			for k, v := range downwardAPIPayload {
    				payload[k] = v
    			}
    		case source.ServiceAccountToken != nil:
    			tp := source.ServiceAccountToken
    
    			// When FsGroup is set, we depend on SetVolumeOwnership to
    			// change from 0600 to 0640.
    			mode := *s.source.DefaultMode
    Registered: Sat Jun 15 01:39:40 UTC 2024
    - Last Modified: Tue May 14 06:17:25 UTC 2024
    - 12.8K bytes
    - Viewed (0)
Back to top