- Sort Score
- Result 10 results
- Languages All
Results 11 - 18 of 18 for tlsOptions (0.19 sec)
-
cmd/kubelet/app/server.go
} // Specify allowed CAs for client certificates tlsOptions.Config.ClientCAs = clientCAs // Populate PeerCertificates in requests, but don't reject connections without verified certificates tlsOptions.Config.ClientAuth = tls.RequestClientCert } return tlsOptions, nil } // setContentTypeForClient sets the appropriate content type into the rest config
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Fri Jun 07 00:05:34 UTC 2024 - 53.9K bytes - Viewed (0) -
pkg/kubemark/hollow_kubelet.go
Cloud: nil, OSInterface: &containertest.FakeOS{}, ContainerManager: containerManager, VolumePlugins: volumePlugins(), TLSOptions: nil, OOMAdjuster: oom.NewFakeOOMAdjuster(), Mounter: &mount.FakeMounter{}, Subpather: &subpath.FakeSubpath{},
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Fri Jun 07 17:10:54 UTC 2024 - 7.8K bytes - Viewed (0) -
pkg/kubelet/kubelet.go
} } else if kubeDeps.TLSOptions.CertFile != "" && kubeDeps.TLSOptions.KeyFile != "" && utilfeature.DefaultFeatureGate.Enabled(features.ReloadKubeletServerCertificateFile) { klet.serverCertificateManager, err = kubeletcertificate.NewKubeletServerCertificateDynamicFileManager(kubeDeps.TLSOptions.CertFile, kubeDeps.TLSOptions.KeyFile) if err != nil {
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Fri Jun 14 16:09:17 UTC 2024 - 126.1K bytes - Viewed (0) -
pkg/istio-agent/agent_test.go
meta.Namespace = "fake-namespace" meta.ServiceAccount = "fake-sa" meta.ProxyConfig = pc return meta } func setupCa(t *testing.T, auth *security.FakeAuthenticator) *mock.CAServer { t.Helper() opt := tlsOptions(t) s, err := mock.NewCAServerWithKeyCert(0, testutil.ReadFile(t, filepath.Join(env.IstioSrc, "./tests/testdata/certs/pilot/ca-key.pem")),
Registered: Fri Jun 14 15:00:06 UTC 2024 - Last Modified: Thu May 16 22:12:28 UTC 2024 - 33.4K bytes - Viewed (0) -
pkg/istio-agent/xds_proxy.go
func (p *XdsProxy) getTLSOptions(agent *Agent) (*istiogrpc.TLSOptions, error) { if agent.proxyConfig.ControlPlaneAuthPolicy == meshconfig.AuthenticationPolicy_NONE { return nil, nil } xdsCACertPath, err := agent.FindRootCAForXDS() if err != nil { return nil, fmt.Errorf("failed to find root CA cert for XDS: %v", err) } key, cert := agent.GetKeyCertsForXDS() return &istiogrpc.TLSOptions{ RootCert: xdsCACertPath,
Registered: Fri Jun 14 15:00:06 UTC 2024 - Last Modified: Thu May 16 22:12:28 UTC 2024 - 27.9K bytes - Viewed (0) -
pkg/kubelet/kubelet_test.go
cadvisor.EXPECT().ImagesFsInfo().Return(cadvisorapiv2.FsInfo{ Usage: 400, Capacity: 1000, Available: 600, }, nil).AnyTimes() tlsOptions := &server.TLSOptions{ Config: &tls.Config{ MinVersion: 0, }, } fakeRuntime, endpoint := createAndStartFakeRemoteRuntime(t) defer func() { fakeRuntime.Stop() }()
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Fri Jun 14 16:09:17 UTC 2024 - 106.9K bytes - Viewed (0) -
pilot/pkg/networking/core/listener_inbound.go
// exact, just best effort optimization filterChains := make([]*listener.FilterChain, 0, 1+5) filterChains = append(filterChains, buildInboundBlackhole(lb)) mtlsOptions := lb.authnBuilder.ForPassthrough() for _, mtls := range mtlsOptions { cc := inboundChainConfig{ port: model.ServiceInstancePort{ ServicePort: &model.Port{ Name: model.VirtualInboundListenerName,
Registered: Fri Jun 14 15:00:06 UTC 2024 - Last Modified: Thu Jun 13 01:56:28 UTC 2024 - 35.1K bytes - Viewed (0) -
pilot/pkg/config/kube/gateway/conversion_test.go
name: "reference-policy-tcp", validationIgnorer: crdvalidation.NewValidationIgnorer( "istio-system/^not-allowed-echo-", ), }, {name: "serviceentry"}, {name: "eastwest"}, {name: "eastwest-tlsoption"}, {name: "eastwest-labelport"}, {name: "eastwest-remote"}, {name: "alias"}, {name: "mcs"}, {name: "route-precedence"}, {name: "waypoint"}, {name: "isolation"}, }
Registered: Fri Jun 14 15:00:06 UTC 2024 - Last Modified: Wed May 08 20:24:52 UTC 2024 - 34.9K bytes - Viewed (0)