- Sort Score
- Result 10 results
- Languages All
Results 1 - 10 of 403 for privilege (0.35 sec)
-
manifests/charts/istio-cni/values.yaml
# Note this gives the DaemonSet a relatively high privilege, as modifying pod metadata/status can have wider impacts. labelPods: false # deletePods will delete any broken pod. These will then be rescheduled, hopefully onto a node that is fully ready. # Note this gives the DaemonSet a relatively high privilege, as it can delete any Pod. deletePods: false
Registered: Fri Jun 14 15:00:06 UTC 2024 - Last Modified: Tue May 21 18:32:01 UTC 2024 - 5.2K bytes - Viewed (0) -
cni/pkg/util/podutil.go
Patch( context.Background(), pod.Name, types.MergePatchType, annotationPatch, metav1.PatchOptions{}, // Both "pods" and "pods/status" can mutate the metadata. However, pods/status is lower privilege, so we use that instead. "status", ) return err } func AnnotateUnenrollPod(client kubernetes.Interface, pod *metav1.ObjectMeta) error {
Registered: Fri Jun 14 15:00:06 UTC 2024 - Last Modified: Fri May 31 17:18:11 UTC 2024 - 4.4K bytes - Viewed (0) -
tools/istio-iptables/pkg/log/nflog.go
"istio.io/istio/pkg/env" "istio.io/istio/pkg/log" ) var TraceLoggingEnabled = env.Register( "IPTABLES_TRACE_LOGGING", false, "When enable, all iptables actions will be logged. "+ "This requires NET_ADMIN privilege and has noisy logs; as a result, this is intended for debugging only").Get() var iptablesTrace = log.RegisterScope("iptables", "trace logs for iptables") // ReadNFLOGSocket reads from the nflog socket, sending output to logs.
Registered: Fri Jun 14 15:00:06 UTC 2024 - Last Modified: Thu Jun 06 15:59:40 UTC 2024 - 2.8K bytes - Viewed (0) -
okhttp-testing-support/src/main/kotlin/okhttp3/internal/concurrent/TaskFaker.kt
* This class ensures that at most one thread is running at a time. This is initially the JUnit test * thread, which yields its execution privilege while calling [runTasks], [runNextTask], or * [advanceUntil]. These functions don't return until the task threads are all idle. * * Task threads release their execution privilege in these ways: * * * By yielding in [TaskRunner.Backend.coordinatorWait]. * * By yielding in [BlockingQueue.poll].
Registered: Sun Jun 16 04:42:17 UTC 2024 - Last Modified: Mon Apr 29 00:33:04 UTC 2024 - 12.6K bytes - Viewed (0) -
manifests/charts/istio-cni/templates/daemonset.yaml
port: 8000 securityContext: privileged: true # always requires privilege to be useful (install node plugin, etc) runAsGroup: 0 runAsUser: 0 runAsNonRoot: false # Both ambient and sidecar repair mode require elevated node privileges to function. # But we don't need _everything_ in `privileged`, so drop+readd capabilities based on feature.
Registered: Fri Jun 14 15:00:06 UTC 2024 - Last Modified: Fri May 17 21:52:29 UTC 2024 - 7.9K bytes - Viewed (0) -
src/cmd/go/testdata/script/mod_tidy_compat_ambiguous.txt
# root of the module graph contains the package), whereas it is ambiguous in # Go 1.16 (because two different modules contain plausible packages and Go 1.16 # does not privilege roots above other dependencies). # # However, the overall build list is identical for both versions. cp go.mod go.mod.orig ! go mod tidy
Registered: Wed Jun 12 16:32:35 UTC 2024 - Last Modified: Thu May 30 14:56:56 UTC 2024 - 4.8K bytes - Viewed (0) -
platforms/core-runtime/base-services/src/main/java/org/gradle/internal/SystemProperties.java
} public String getLineSeparator() { return System.getProperty("line.separator"); } /** * @deprecated Using the temporary directory on UNIX-based systems can lead to local privilege escalation or local sensitive information disclosure vulnerabilities. */ @Deprecated @SuppressWarnings("InlineMeSuggester") public String getJavaIoTmpDir() {
Registered: Wed Jun 12 18:38:38 UTC 2024 - Last Modified: Wed May 29 06:47:40 UTC 2024 - 7.6K bytes - Viewed (0) -
src/net/textproto/reader_test.go
"Content-Language: en\r\n" + "SID : 0\r\n" + "Audio Mode : None\r\n" + "Privilege : 127\r\n\r\n") m, err := r.ReadMIMEHeader() want := MIMEHeader{ "Foo": {"bar"}, "Content-Language": {"en"}, "SID ": {"0"}, "Audio Mode ": {"None"}, "Privilege ": {"127"}, } if !reflect.DeepEqual(m, want) || err != nil {
Registered: Wed Jun 12 16:32:35 UTC 2024 - Last Modified: Tue Mar 05 18:31:56 UTC 2024 - 14.7K bytes - Viewed (0) -
cni/pkg/repair/repaircontroller.go
patchBytes := fmt.Sprintf(`{"metadata":{"labels":{%q:%q}}}`, c.cfg.LabelKey, c.cfg.LabelValue) // Both "pods" and "pods/status" can mutate the metadata. However, pods/status is lower privilege, so we use that instead. _, err := c.client.Kube().CoreV1().Pods(pod.Namespace).Patch(context.Background(), pod.Name, types.MergePatchType, []byte(patchBytes), metav1.PatchOptions{}, "status") if err != nil {
Registered: Fri Jun 14 15:00:06 UTC 2024 - Last Modified: Sat Feb 10 00:31:55 UTC 2024 - 10.4K bytes - Viewed (0) -
common-protos/k8s.io/api/policy/v1beta1/generated.proto
repeated PodSecurityPolicy items = 2; } // PodSecurityPolicySpec defines the policy enforced. message PodSecurityPolicySpec { // privileged determines if a pod can request to be run as privileged. // +optional optional bool privileged = 1; // defaultAddCapabilities is the default set of capabilities that will be added to the container
Registered: Fri Jun 14 15:00:06 UTC 2024 - Last Modified: Mon Mar 11 18:43:24 UTC 2024 - 19.6K bytes - Viewed (0)