- Sort Score
- Result 10 results
- Languages All
Results 1 - 9 of 9 for caps (0.15 sec)
-
istioctl/pkg/writer/ztunnel/configdump/services.go
// limitations under the License. package configdump import ( "cmp" "encoding/json" "fmt" "strings" "sigs.k8s.io/yaml" "istio.io/istio/pkg/maps" "istio.io/istio/pkg/slices" ) // ServiceFilter is used to pass filter information into service based config writer print functions type ServiceFilter struct { Namespace string }
Go - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Tue Apr 23 21:30:30 GMT 2024 - 2.8K bytes - Viewed (0) -
cni/README.md
- CAP_SYS_ADMIN - CAP_NET_ADMIN - CAP_NET_RAW ## Ambient mode details Fundamentally, this component is responsible for the following:
Plain Text - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Fri May 03 19:29:42 GMT 2024 - 12.3K bytes - Viewed (0) -
istioctl/pkg/writer/ztunnel/configdump/connections.go
"fmt" "net" "strings" "sigs.k8s.io/yaml" "istio.io/istio/pkg/maps" "istio.io/istio/pkg/slices" ) type ConnectionsFilter struct { Namespace string Direction string Raw bool } func (c *ConfigWriter) PrintConnectionsDump(filter ConnectionsFilter, outputFormat string) error { d := c.ztunnelDump workloads := maps.Values(d.WorkloadState)
Go - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Mon Apr 22 15:39:28 GMT 2024 - 3.3K bytes - Viewed (0) -
architecture/ambient/ztunnel.md
In addition, they are more clear and strictly typed; using Envoy types would require us to put a lot of information in untyped `metadata` maps. With this in mind, Ztunnel supports two xDS resources: `Address` and `Authorization`. ### Address Type The primary configuration consumed by Ztunnel is the [`Address` resource](../../pkg/workloadapi/workload.proto).
Plain Text - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Thu Apr 25 22:35:16 GMT 2024 - 16.6K bytes - Viewed (0) -
istioctl/pkg/writer/ztunnel/configdump/policies.go
// limitations under the License. package configdump import ( "cmp" "encoding/json" "fmt" "strings" "sigs.k8s.io/yaml" "istio.io/istio/pkg/maps" "istio.io/istio/pkg/slices" ) // PolicyFilter is used to pass filter information into service based config writer print functions type PolicyFilter struct { Namespace string }
Go - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Tue Apr 23 21:30:30 GMT 2024 - 2.5K bytes - Viewed (0) -
manifests/charts/istio-cni/values.yaml
# Note the pod will be crashlooping, so this may take a few minutes to become fully functional based on when the retry occurs. # This requires no RBAC privilege, but does require `securityContext.privileged/CAP_SYS_ADMIN`. repairPods: true initContainerName: "istio-validation" brokenPodLabelKey: "cni.istio.io/uninitialized" brokenPodLabelValue: "true"
Others - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Tue Apr 30 22:24:38 GMT 2024 - 5.2K bytes - Viewed (1) -
common/config/.golangci.yml
Others - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Mon Apr 22 19:22:39 GMT 2024 - 11K bytes - Viewed (0) -
manifests/charts/istio-cni/templates/daemonset.yaml
# privileged is redundant with CAP_SYS_ADMIN # since it's redundant, hardcode it to `true`, then manually drop ALL + readd granular # capabilities we actually require capabilities: drop: - ALL add: # CAP_NET_ADMIN is required to allow ipset and route table access - NET_ADMIN
Others - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Fri May 03 19:29:42 GMT 2024 - 9.4K bytes - Viewed (0) -
operator/cmd/mesh/manifest-generate_test.go
_, _ = runManifestGenerate([]string{inPathBase}, "", liveCharts, []string{"templates/deployment.yaml"}) } func TestBogusControlPlaneSec(t *testing.T) { inPathBase := filepath.Join(testDataDir, "input/bogus_cps.yaml") _, err := runManifestGenerate([]string{inPathBase}, "", liveCharts, []string{"templates/deployment.yaml"}) if err != nil { t.Fatal(err) } } func TestInstallPackagePath(t *testing.T) {
Go - Registered: Wed May 08 22:53:08 GMT 2024 - Last Modified: Thu Apr 18 18:16:49 GMT 2024 - 43.5K bytes - Viewed (0)