- Sort Score
- Result 10 results
- Languages All
Results 21 - 30 of 63 for impersonate (0.23 sec)
-
pkg/kube/util.go
ClientKey: auths.ClientKey, ClientKeyData: auths.ClientKeyData, Token: auths.Token, TokenFile: auths.TokenFile, Impersonate: auths.Impersonate, ImpersonateGroups: auths.ImpersonateGroups, ImpersonateUserExtra: auths.ImpersonateUserExtra, Username: auths.Username, Password: auths.Password,
Registered: Fri Jun 14 15:00:06 UTC 2024 - Last Modified: Thu Jun 06 05:10:23 UTC 2024 - 18.6K bytes - Viewed (0) -
pkg/apis/rbac/helpers.go
} // if resource names are set, then the verb must not be list, watch, create, or deletecollection // since verbs are largely opaque, we don't want to accidentally prevent things like "impersonate", so // we will backlist common mistakes, not whitelist acceptable options. if len(r.PolicyRule.ResourceNames) != 0 { illegalVerbs := []string{} for _, verb := range r.PolicyRule.Verbs { switch verb {
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Sun Feb 23 15:11:00 UTC 2020 - 12.1K bytes - Viewed (0) -
plugin/pkg/auth/authorizer/rbac/bootstrappolicy/testdata/cluster-roles.yaml
- pods/proxy - secrets - services/proxy verbs: - get - list - watch - apiGroups: - "" resources: - serviceaccounts verbs: - impersonate - apiGroups: - "" resources: - pods - pods/attach - pods/exec - pods/portforward - pods/proxy verbs: - create - delete - deletecollection
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Tue Jul 18 08:11:08 UTC 2023 - 24.1K bytes - Viewed (0) -
pkg/security/security.go
CertSigner = "CertSigner" // ImpersonatedIdentity declares the identity we are requesting a certificate on behalf of. // This is constrained to only allow identities in CATrustedNodeAccounts, and only to impersonate identities // on their node. ImpersonatedIdentity = "ImpersonatedIdentity" ) type ImpersonatedIdentityContextKey struct{}
Registered: Fri Jun 14 15:00:06 UTC 2024 - Last Modified: Thu Jun 13 17:48:28 UTC 2024 - 19.1K bytes - Viewed (0) -
cmd/kubeadm/app/apis/kubeadm/v1beta3/types.go
// UnsafeSkipCAVerification allows token-based discovery // without CA verification via CACertHashes. This can weaken // the security of kubeadm since other nodes can impersonate the control-plane. // +optional UnsafeSkipCAVerification bool `json:"unsafeSkipCAVerification,omitempty"` }
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Sat May 11 10:21:20 UTC 2024 - 19.6K bytes - Viewed (0) -
cmd/kubeadm/app/cmd/join.go
the --discovery-token-unsafe-skip-ca-verification flag to disable this verification. This weakens the kubeadm security model since other nodes can potentially impersonate the Kubernetes Control Plane. The TLS bootstrap mechanism is also driven via a shared token. This is used to temporarily authenticate with the Kubernetes Control Plane to submit a
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Fri Feb 16 15:33:38 UTC 2024 - 25.2K bytes - Viewed (0) -
plugin/pkg/auth/authorizer/rbac/bootstrappolicy/policy.go
rbacv1helpers.NewRule(Read...).Groups(legacyGroup).Resources("pods/attach", "pods/proxy", "pods/exec", "pods/portforward", "secrets", "services/proxy").RuleOrDie(), rbacv1helpers.NewRule("impersonate").Groups(legacyGroup).Resources("serviceaccounts").RuleOrDie(), rbacv1helpers.NewRule(Write...).Groups(legacyGroup).Resources("pods", "pods/attach", "pods/proxy", "pods/exec", "pods/portforward").RuleOrDie(),
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Fri Mar 08 19:25:10 UTC 2024 - 34.4K bytes - Viewed (0) -
src/os/exec/exec_test.go
if poll.IsPollDescriptor(fd) { continue } if fdtest.Exists(fd) { haveUnexpectedFDs = true return } } } // TestMain allows the test binary to impersonate many other binaries, // some of which may manipulate os.Stdin, os.Stdout, and/or os.Stderr // (and thus cannot run as an ordinary Test function, since the testing // package monkey-patches those variables before running tests).
Registered: Wed Jun 12 16:32:35 UTC 2024 - Last Modified: Fri Jun 07 20:13:53 UTC 2024 - 48.4K bytes - Viewed (0) -
platforms/documentation/docs/src/docs/userguide/optimizing-performance/build-cache/build_cache.adoc
Enabling this option is a security risk, as it allows any cache server to impersonate the intended server. It should only be used as a temporary measure or in very tightly controlled network environments. .Allow untrusted cache server ====
Registered: Wed Jun 12 18:38:38 UTC 2024 - Last Modified: Wed May 15 11:30:10 UTC 2024 - 26.1K bytes - Viewed (0) -
cmd/kubeadm/app/apis/kubeadm/types.go
CACertHashes []string // UnsafeSkipCAVerification allows token-based discovery // without CA verification via CACertHashes. This can weaken // the security of kubeadm since other nodes can impersonate the control-plane. UnsafeSkipCAVerification bool } // FileDiscovery is used to specify a file or URL to a kubeconfig file from which to load cluster information type FileDiscovery struct {
Registered: Sat Jun 15 01:39:40 UTC 2024 - Last Modified: Fri May 17 03:12:52 UTC 2024 - 32.6K bytes - Viewed (0)