Search Options

Results per page
Sort
Preferred Languages
Advance

Results 1 - 10 of 65 for supplementalGroupsPolicy (0.41 sec)

  1. pkg/kubelet/kuberuntime/security_context.go

    			}
    		}
    
    		if podSc.SupplementalGroupsPolicy != nil {
    			policyValue, ok := runtimeapi.SupplementalGroupsPolicy_value[string(*podSc.SupplementalGroupsPolicy)]
    			if !ok {
    				return nil, fmt.Errorf("unsupported supplementalGroupsPolicy: %s", string(*podSc.SupplementalGroupsPolicy))
    			}
    			synthesized.SupplementalGroupsPolicy = runtimeapi.SupplementalGroupsPolicy(policyValue)
    		}
    	}
    Registered: Sat Jun 15 01:39:40 UTC 2024
    - Last Modified: Wed May 29 22:40:29 UTC 2024
    - 5.2K bytes
    - Viewed (0)
  2. pkg/kubelet/kuberuntime/kuberuntime_sandbox_linux_test.go

    	}
    
    	return pod
    }
    
    func newSupplementalGroupsPolicyPod(supplementalGroupsPolicy *v1.SupplementalGroupsPolicy) *v1.Pod {
    	pod := newTestPod()
    	if pod.Spec.SecurityContext == nil {
    		pod.Spec.SecurityContext = &v1.PodSecurityContext{}
    	}
    	pod.Spec.SecurityContext.SupplementalGroupsPolicy = supplementalGroupsPolicy
    	return pod
    }
    
    Registered: Sat Jun 15 01:39:40 UTC 2024
    - Last Modified: Wed May 29 22:40:29 UTC 2024
    - 8K bytes
    - Viewed (0)
  3. staging/src/k8s.io/client-go/applyconfigurations/core/v1/podsecuritycontext.go

    	SupplementalGroups       []int64                                          `json:"supplementalGroups,omitempty"`
    	SupplementalGroupsPolicy *corev1.SupplementalGroupsPolicy                 `json:"supplementalGroupsPolicy,omitempty"`
    	FSGroup                  *int64                                           `json:"fsGroup,omitempty"`
    Registered: Sat Jun 15 01:39:40 UTC 2024
    - Last Modified: Wed May 29 22:40:29 UTC 2024
    - 8.1K bytes
    - Viewed (0)
  4. pkg/kubelet/kuberuntime/kuberuntime_sandbox.go

    			}
    		}
    		if sc.SupplementalGroupsPolicy != nil {
    			policyValue, ok := runtimeapi.SupplementalGroupsPolicy_value[string(*sc.SupplementalGroupsPolicy)]
    			if !ok {
    				return nil, fmt.Errorf("unsupported supplementalGroupsPolicy: %s", string(*sc.SupplementalGroupsPolicy))
    			}
    			lc.SecurityContext.SupplementalGroupsPolicy = runtimeapi.SupplementalGroupsPolicy(policyValue)
    		}
    
    Registered: Sat Jun 15 01:39:40 UTC 2024
    - Last Modified: Wed May 29 22:40:29 UTC 2024
    - 13.6K bytes
    - Viewed (0)
  5. pkg/kubelet/kuberuntime/kuberuntime_container_linux_test.go

    		name           string
    		pod            *v1.Pod
    		expected       runtimeapi.SupplementalGroupsPolicy
    		expectErr      bool
    		expectedErrMsg string
    	}{{
    		name: "Merge SupplementalGroupsPolicy should convert to Merge",
    		pod: &v1.Pod{
    			Spec: v1.PodSpec{
    				SecurityContext: &v1.PodSecurityContext{
    					SupplementalGroupsPolicy: &supplementalGroupsPolicyMerge,
    				},
    				Containers: []v1.Container{
    Registered: Sat Jun 15 01:39:40 UTC 2024
    - Last Modified: Wed May 29 22:40:29 UTC 2024
    - 41K bytes
    - Viewed (0)
  6. pkg/kubelet/kuberuntime/kuberuntime_container_test.go

    		featureEnabled bool
    	}{
    		"non nil user, SupplementalGroupsPolicy is disabled": {
    			input: &runtimeapi.ContainerUser{
    				Linux: &runtimeapi.LinuxContainerUser{
    					Uid:                0,
    					Gid:                0,
    					SupplementalGroups: []int64{10},
    				},
    			},
    			expected:       nil,
    			featureEnabled: false,
    		},
    		"empty user, SupplementalGroupsPolicy is disabled": {
    Registered: Sat Jun 15 01:39:40 UTC 2024
    - Last Modified: Wed May 29 22:40:29 UTC 2024
    - 28K bytes
    - Viewed (0)
  7. pkg/api/pod/util.go

    		}
    	}
    
    	// If the feature is disabled and not in use, drop the SupplementalGroupsPolicy field.
    	if !utilfeature.DefaultFeatureGate.Enabled(features.SupplementalGroupsPolicy) && !supplementalGroupsPolicyInUse(oldPodSpec) {
    		// Drop the field in podSpec only if SecurityContext is not nil.
    		// If it is nil, there is no need to set supplementalGroupsPolicy=nil (it will be nil too).
    		if podSpec.SecurityContext != nil {
    Registered: Sat Jun 15 01:39:40 UTC 2024
    - Last Modified: Wed May 29 22:40:29 UTC 2024
    - 41.3K bytes
    - Viewed (0)
  8. pkg/features/kube_features.go

    	// owner: @everpeace
    	// kep: https://kep.k8s.io/3619
    	// alpha: v1.31
    	//
    	// Enable SupplementalGroupsPolicy feature in PodSecurityContext
    	SupplementalGroupsPolicy featuregate.Feature = "SupplementalGroupsPolicy"
    )
    
    func init() {
    	runtime.Must(utilfeature.DefaultMutableFeatureGate.Add(defaultKubernetesFeatureGates))
    
    Registered: Sat Jun 15 01:39:40 UTC 2024
    - Last Modified: Wed Jun 12 22:51:23 UTC 2024
    - 45.2K bytes
    - Viewed (0)
  9. pkg/api/pod/util_test.go

    		pod                         func() *api.Pod
    	}{
    		{
    			description:                 "with SupplementalGroupsPolicy and User",
    			hasSupplementalGroupsPolicy: true,
    			pod:                         podWithSupplementalGroupsPolicy,
    		},
    		{
    			description:                 "without SupplementalGroupsPolicy and User",
    			hasSupplementalGroupsPolicy: false,
    Registered: Sat Jun 15 01:39:40 UTC 2024
    - Last Modified: Wed May 29 22:40:29 UTC 2024
    - 108.8K bytes
    - Viewed (0)
  10. staging/src/k8s.io/api/testdata/HEAD/apps.v1.Deployment.json

              },
              "runAsUser": 2,
              "runAsGroup": 6,
              "runAsNonRoot": true,
              "supplementalGroups": [
                4
              ],
              "supplementalGroupsPolicy": "supplementalGroupsPolicyValue",
              "fsGroup": 5,
              "sysctls": [
                {
                  "name": "nameValue",
                  "value": "valueValue"
                }
              ],
    Registered: Sat Jun 15 01:39:40 UTC 2024
    - Last Modified: Wed May 29 22:40:29 UTC 2024
    - 54.5K bytes
    - Viewed (0)
Back to top