Darren Shepherd
4213ae7031
Update vendor
2019-04-09 10:02:31 -07:00
Darren Shepherd
d9c8ce68ad
Delete anonymous auth
2019-04-08 19:37:51 -07:00
Darren Shepherd
56d0aebecd
Delete oidc
2019-04-08 19:37:51 -07:00
Darren Shepherd
c691249e0b
Delete bootstrap token
2019-04-08 19:37:51 -07:00
Darren Shepherd
5b28c92497
Remove ABAC
2019-04-08 19:37:51 -07:00
Darren Shepherd
c25d2c956e
Remove admission controllers
2019-04-08 19:37:51 -07:00
Darren Shepherd
ef63a2a09f
Delete cloud provider
2019-04-08 17:44:58 -07:00
Darren Shepherd
115e7f7768
Remove BoundServiceAccountTokenVolume
2019-04-08 17:44:39 -07:00
Darren Shepherd
fc0eca9e0c
Remove settings
2019-04-08 17:44:39 -07:00
Darren Shepherd
8a45d36638
Remove imagepolicy
2019-04-08 17:44:39 -07:00
Andrew Kim
2901def8c3
delete the persistentvolume labeler controller
2019-02-26 14:23:20 -05:00
Mike Danese
47043bcac1
enforce that cloud providers are only linked in main or app packages
2019-02-22 11:56:39 -08:00
Kubernetes Prow Robot
0ffd59e403
Merge pull request #74154 from mbohlool/gimli
...
Use Request Object interfaces instead of static scheme that is more appropriate for CRDs
2019-02-19 07:21:53 -08:00
Mehdy Bohlool
0f186323bc
Update generated files
2019-02-16 13:28:48 -08:00
Mehdy Bohlool
cebb4ee2ac
Remove the propagated scheme from the Admission chain
2019-02-16 13:28:47 -08:00
Marek Counts
160ed26c20
autogen files to support new project structure.
2019-02-15 10:29:31 -05:00
Marek Counts
7744f90830
Moved flag and globalflag
...
Moved all flag code from `staging/src/k8s.io/apiserver/pkg/util/[flag|globalflag]` to `component-base/cli/[flag|globalflag]` except for the term function because of unwanted dependencies.
2019-02-15 10:28:13 -05:00
Chao Xu
bed7696876
generated BUILD files
2019-01-30 13:28:48 -08:00
Chao Xu
1281243860
Remove the --storage-versions flag from kube-apiserver.
...
The storage version now is solely decided by the
scheme.PrioritizedVersionsForGroup(). For cohabitating resources, the storage
version will be that of the overriding group as returned by
storageFactory.getStorageGroupResource().
2019-01-30 13:28:48 -08:00
Jordan Liggitt
89b0b0b84b
Clean up initializer-related comments, test data
2019-01-25 12:37:45 -05:00
Kubernetes Prow Robot
d654b49c0e
Merge pull request #73097 from bsalamat/fix_taint_nodes
...
Add NotReady taint to new nodes during admission
2019-01-24 23:46:23 -08:00
Bobby (Babak) Salamat
763cb708d1
Autogenerated files
2019-01-24 10:31:23 -08:00
Bobby (Babak) Salamat
c2a4d2cbdf
Add a default admission controller to taint new nodes on creation.
2019-01-24 10:31:23 -08:00
Jordan Liggitt
1a15d80967
generated
2019-01-23 16:34:44 -05:00
Jordan Liggitt
dc1fa870bf
Remove alpha InitializerConfiguration types, Initializers admission plugin
2019-01-23 11:37:39 -05:00
lovejoy
d437305cbf
Fix the authorization-policy-file description
...
Actually this is in a format like below not a csv format
```json
{"apiVersion": "abac.authorization.kubernetes.io/v1beta1", "kind": "Policy", "spec": {"group":"system:authenticated", "namespace": "*", "resource": "*","apiGroup": "*"}}
{"apiVersion": "abac.authorization.kubernetes.io/v1beta1", "kind": "Policy", "spec": {"group":"system:authenticated", "namespace": "*", "resource": "ingresses","apiGroup": "extensions"}}
{"apiVersion": "abac.authorization.kubernetes.io/v1beta1", "kind": "Policy", "spec": {"group":"system:authenticated", "namespace": "*", "resource": "*","apiGroup": "apiextensions.k8s.io"}}
```
2018-12-24 14:54:34 +08:00
k8s-ci-robot
bd2cb5a72d
Merge pull request #70831 from mikedanese/securesvcacct
...
add BoundServiceAccountTokenVolume feature
2018-11-13 08:54:25 -08:00
Mike Danese
f4ff26679f
add BoundServiceAccountTokenVolume feature
...
* require TokenRequest to be enabled and configured
* bind ca.crt publisher to this feature rather than to TokenRequest
2018-11-12 13:11:47 -08:00
Davanum Srinivas
954996e231
Move from glog to klog
...
- Move from the old github.com/golang/glog to k8s.io/klog
- klog as explicit InitFlags() so we add them as necessary
- we update the other repositories that we vendor that made a similar
change from glog to klog
* github.com/kubernetes/repo-infra
* k8s.io/gengo/
* k8s.io/kube-openapi/
* github.com/google/cadvisor
- Entirely remove all references to glog
- Fix some tests by explicit InitFlags in their init() methods
Change-Id: I92db545ff36fcec83afe98f550c9e630098b3135
2018-11-10 07:50:31 -05:00
walter
2af982abb9
Fixes lint errors in kubeapiserver packages
...
Fixes lint errors in kubeapiserver/admission, kubeapiserver/authorizer,
kubeapiserver/authenticator. Also enables lint testing of these
directories.
Fixed go format.
Fixed changes from config.
2018-11-04 17:22:41 -08:00
Mike Danese
a13b48de94
default api audiences to service account token issuer if available
...
This is a sane default that users can choose to migrate away from later.
2018-10-29 16:40:06 -07:00
Mike Danese
371b1e7fed
promote --service-account-api-audiences to top level kube-apiserver config
...
The service account authenticator isn't the only authenticator that
should respect API audience. The authentication config structure should
reflect that.
2018-10-22 18:21:37 -07:00
k8s-ci-robot
cf3a930938
Merge pull request #69607 from mikedanese/audctx
...
tokenreview: add APIAudiences config to generic API server and augment context
2018-10-15 19:03:43 -07:00
k8s-ci-robot
793b8752d1
Merge pull request #68777 from stewart-yu/patch-1
...
remove unneed parameter in test struct
2018-10-12 16:01:23 -07:00
Mike Danese
21fd8f2041
tokenreview: add APIAudiences config to generic API server and augment context
2018-10-09 22:47:10 -07:00
Christoph Blecker
97b2992dc1
Update gofmt for go1.11
2018-10-05 12:59:38 -07:00
Stewart-YU
5ef8e41215
remove unneed parameter in test struct
...
remove unneed parameter in test struct
2018-09-26 08:59:42 +08:00
Chao Xu
1fb6b5aa69
Deprecation notice of storage-versions flag
2018-08-30 19:45:43 -07:00
yue9944882
f624a4efb8
externalize node admission
...
fixes internal pod annotation reference
completely strip internal informers from authz initialization
2018-08-21 23:33:03 +08:00
Kubernetes Submit Queue
b9544382ba
Merge pull request #67060 from sttts/sttts-unify-insecure-serving
...
Automatic merge from submit-queue. If you want to cherry-pick this change to another branch, please follow the instructions <a href="https://github.com/kubernetes/community/blob/master/contributors/devel/cherry-picks.md ">here</a>.
kube-{apiserver,ctrl-mgr}: unify into DeprecatedInsecureServingOptions
**What this PR does / why we need it**:
**Which issue(s) this PR fixes** *(optional, in `fixes #<issue number>(, fixes #<issue_number>, ...)` format, will close the issue(s) when PR gets merged)*:
Fixes #
**Special notes for your reviewer**:
**Release note**:
```release-note
```
2018-08-17 08:50:36 -07:00
Dr. Stefan Schimanski
c2724793e8
Update bazel
2018-08-17 08:57:21 +02:00
Dr. Stefan Schimanski
d787213d1b
kube-apiserver: switch apiserver's DeprecatedInsecureServingOptions
2018-08-17 08:56:47 +02:00
Dr. Stefan Schimanski
1d9a896066
apiserver: move controller-manager's insecure config into apiserver
2018-08-17 08:56:46 +02:00
hangaoshuai
cacf18f859
add unit test for func ToAuthenticationConfig
2018-08-16 19:24:11 +08:00
hangaoshuai
4157f5a1ae
add unit test for Authentication Validate
2018-08-16 18:13:58 +08:00
yue9944882
e8ae7887a5
This is a combination of 3 commits.
...
refactor storage factory options
review: minor changes
1. make storage factory config complete with options
2. make BuildGenericConfig private
review: move codes
2018-08-06 22:29:10 +08:00
Dr. Stefan Schimanski
e15ac9eb72
kube-apiserver: disallow --secure-port 0
2018-07-09 14:03:08 +02:00
Dr. Stefan Schimanski
1575e17365
kube-apiserver: drop unused loopback token in insecure mode
2018-07-04 19:15:11 +02:00
ravisantoshgudimetla
d5fa41b920
Build file generated
2018-07-02 22:25:45 -04:00
ravisantoshgudimetla
f1c202d392
Add priority to defaultOn plugins list
2018-07-02 22:25:40 -04:00