Merge pull request #42646 from my-git9/fdsfadf
[zh-cn] sync config-api/apiserver-* client-* imagepolicypull/42749/head
commit
9867b6d2a0
|
@ -103,7 +103,7 @@ Event 结构包含可出现在 API 审计日志中的所有信息。
|
|||
</tr>
|
||||
|
||||
<tr><td><code>user</code> <B><!--[Required]-->[必需]</B><br/>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.27/#userinfo-v1-authentication"><code>authentication/v1.UserInfo</code></a>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.28/#userinfo-v1-authentication-k8s-io"><code>authentication/v1.UserInfo</code></a>
|
||||
</td>
|
||||
<td>
|
||||
<p>
|
||||
|
@ -114,7 +114,7 @@ Event 结构包含可出现在 API 审计日志中的所有信息。
|
|||
</tr>
|
||||
|
||||
<tr><td><code>impersonatedUser</code><br/>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.27/#userinfo-v1-authentication"><code>authentication/v1.UserInfo</code></a>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.28/#userinfo-v1-authentication-k8s-io"><code>authentication/v1.UserInfo</code></a>
|
||||
</td>
|
||||
<td>
|
||||
<p>
|
||||
|
@ -189,7 +189,7 @@ Note: All but the last IP can be arbitrarily set by the client.
|
|||
</tr>
|
||||
|
||||
<tr><td><code>responseStatus</code><br/>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.27/#status-v1-meta"><code>meta/v1.Status</code></a>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.28/#status-v1-meta"><code>meta/v1.Status</code></a>
|
||||
</td>
|
||||
<td>
|
||||
<p>
|
||||
|
@ -243,7 +243,7 @@ Note: All but the last IP can be arbitrarily set by the client.
|
|||
</tr>
|
||||
|
||||
<tr><td><code>requestReceivedTimestamp</code><br/>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.27/#microtime-v1-meta"><code>meta/v1.MicroTime</code></a>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.28/#microtime-v1-meta"><code>meta/v1.MicroTime</code></a>
|
||||
</td>
|
||||
<td>
|
||||
<!--Time the request reached the apiserver.-->
|
||||
|
@ -254,7 +254,7 @@ Note: All but the last IP can be arbitrarily set by the client.
|
|||
</tr>
|
||||
|
||||
<tr><td><code>stageTimestamp</code><br/>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.27/#microtime-v1-meta"><code>meta/v1.MicroTime</code></a>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.28/#microtime-v1-meta"><code>meta/v1.MicroTime</code></a>
|
||||
</td>
|
||||
<td>
|
||||
<p>
|
||||
|
@ -309,7 +309,7 @@ EventList 是审计事件(Event)的列表。
|
|||
<tr><td><code>kind</code><br/>string</td><td><code>EventList</code></td></tr>
|
||||
|
||||
<tr><td><code>metadata</code><br/>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.27/#listmeta-v1-meta"><code>meta/v1.ListMeta</code></a>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.28/#listmeta-v1-meta"><code>meta/v1.ListMeta</code></a>
|
||||
</td>
|
||||
<td>
|
||||
<span class="text-muted"><!--No description provided.-->列表结构元数据</span>
|
||||
|
@ -351,7 +351,7 @@ Policy 定义的是审计日志的配置以及不同类型请求的日志记录
|
|||
<tr><td><code>kind</code><br/>string</td><td><code>Policy</code></td></tr>
|
||||
|
||||
<tr><td><code>metadata</code><br/>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.27/#objectmeta-v1-meta"><code>meta/v1.ObjectMeta</code></a>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.28/#objectmeta-v1-meta"><code>meta/v1.ObjectMeta</code></a>
|
||||
</td>
|
||||
<td>
|
||||
<p>
|
||||
|
@ -440,7 +440,7 @@ PolicyList 是由审计策略(Policy)组成的列表。
|
|||
<tr><td><code>kind</code><br/>string</td><td><code>PolicyList</code></td></tr>
|
||||
|
||||
<tr><td><code>metadata</code><br/>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.27/#listmeta-v1-meta"><code>meta/v1.ListMeta</code></a>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.28/#listmeta-v1-meta"><code>meta/v1.ListMeta</code></a>
|
||||
</td>
|
||||
<td>
|
||||
<span class="text-muted"><!--No description provided.-->列表结构元数据。</span>
|
||||
|
@ -494,19 +494,13 @@ GroupResources 代表的是某 API 组中的资源类别。
|
|||
<td>
|
||||
<!--
|
||||
Resources is a list of resources this rule applies to.
|
||||
<p>For example:</p>
|
||||
<ul>
|
||||
<li><code>pods</code> matches pods.</li>
|
||||
<li><code>pods/log</code> matches the log subresource of pods.</li>
|
||||
<li><code>*<code> matches all resources and their subresources.</li>
|
||||
<li><code>pods/*</code> matches all subresources of pods.</li>
|
||||
<li><code>*/scale</code> matches all scale subresources.</li>
|
||||
</ul>
|
||||
<p>For example:
|
||||
'pods' matches pods.
|
||||
'pods/log' matches the log subresource of pods.
|
||||
'<em>' matches all resources and their subresources.
|
||||
'pods/</em>' matches all subresources of pods.
|
||||
'*/scale' matches all scale subresources.</p>
|
||||
-->
|
||||
<p>
|
||||
字段 resources 是此规则所适用的资源的列表。
|
||||
</p>
|
||||
<br/>
|
||||
<p>例如:</p>
|
||||
<ul>
|
||||
<li><code>pods</code> 匹配 Pod;</li>
|
||||
|
@ -773,12 +767,10 @@ PolicyRule 包含一个映射,基于元数据将请求映射到某审计级别
|
|||
<td>
|
||||
<!--
|
||||
NonResourceURLs is a set of URL paths that should be audited.
|
||||
<code>*<code>s are allowed, but only as the full, final step in the path.
|
||||
Examples:</p>
|
||||
<ul>
|
||||
<li>"/metrics" - Log requests for apiserver metrics</li>
|
||||
<li>"/healthz*" - Log all health checks</li>
|
||||
</ul>
|
||||
<em>s are allowed, but only as the full, final step in the path.
|
||||
Examples:
|
||||
"/metrics" - Log requests for apiserver metrics
|
||||
"/healthz</em>" - Log all health checks</p>
|
||||
-->
|
||||
|
||||
<p>
|
||||
|
@ -864,4 +856,3 @@ Stage defines the stages in request handling that audit events may be generated.
|
|||
-->
|
||||
Stage 定义在请求处理过程中可以生成审计事件的阶段。
|
||||
</p>
|
||||
|
||||
|
|
|
@ -29,10 +29,8 @@ Package v1 is the v1 version of the API.
|
|||
## `EncryptionConfiguration` {#apiserver-config-k8s-io-v1-EncryptionConfiguration}
|
||||
|
||||
<!--
|
||||
EncryptionConfiguration stores the complete configuration for encryption providers.
|
||||
It also allows the use of wildcards to specify the resources that should be encrypted.
|
||||
Use <code>*.<group></code> to encrypt all resources within a group or <code>*.*</code> to encrypt all resources.
|
||||
<code>*.</code> can be used to encrypt all resource in the core group. <code>*.*</code> will encrypt all
|
||||
Use '<em>.<!!-- raw HTML omitted -->' to encrypt all resources within a group or '</em>.<em>' to encrypt all resources.
|
||||
'</em>.' can be used to encrypt all resource in the core group. '<em>.</em>' will encrypt all
|
||||
resources, even custom resources that are added after API server start.
|
||||
Use of wildcards that overlap within the same resource list or across multiple
|
||||
entries are not allowed since part of the configuration would be ineffective.
|
||||
|
@ -399,10 +397,10 @@ ResourceConfiguration 中保存资源配置。
|
|||
<p>
|
||||
<!--
|
||||
resources is a list of kubernetes resources which have to be encrypted. The resource names are derived from <code>resource</code> or <code>resource.group</code> of the group/version/resource.
|
||||
eg: <code>pandas.awesome.bears.example</code> is a custom resource with 'group': <code>awesome.bears.example</code>, 'resource': <code>pandas</code>.
|
||||
Use <code>*.*</code> to encrypt all resources and <code>*.<group></code>' to encrypt all resources in a specific group.
|
||||
eg: <code>*.awesome.bears.example</code> will encrypt all resources in the group <code>awesome.bears.example</code>.
|
||||
eg: <code>*.</code> will encrypt all resources in the core group (such as pods, configmaps, etc).
|
||||
eg: pandas.awesome.bears.example is a custom resource with 'group': awesome.bears.example, 'resource': pandas.
|
||||
Use '<em>.</em>' to encrypt all resources and '<em>.< raw HTML omitted >' to encrypt all resources in a specific group.
|
||||
eg: '</em>.awesome.bears.example' will encrypt all resources in the group 'awesome.bears.example'.
|
||||
eg: '*.' will encrypt all resources in the core group (such as pods, configmaps, etc).</p>
|
||||
-->
|
||||
<code>resources</code> 是必须要加密的 Kubernetes 资源的列表。
|
||||
资源名称来自于组/版本/资源的 <code>resource</code> 或 <code>resource.group</code>。
|
||||
|
|
|
@ -259,7 +259,7 @@ itself should at least be protected via file permissions.
|
|||
<thead><tr><th width="30%"><!--Field-->字段</th><th><!--Description-->描述</th></tr></thead>
|
||||
<tbody>
|
||||
<tr><td><code>expirationTimestamp</code><br/>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.27/#time-v1-meta"><code>meta/v1.Time</code></a>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.28/#time-v1-meta"><code>meta/v1.Time</code></a>
|
||||
</td>
|
||||
<td>
|
||||
<!--ExpirationTimestamp indicates a time when the provided credentials expire.-->
|
||||
|
@ -295,4 +295,3 @@ itself should at least be protected via file permissions.
|
|||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
|
|
@ -290,7 +290,7 @@ exec 插件本身至少应通过文件访问许可来实施保护。</p>
|
|||
|
||||
|
||||
<tr><td><code>expirationTimestamp</code><br/>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.27/#time-v1-meta"><code>meta/v1.Time</code></a>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.28/#time-v1-meta"><code>meta/v1.Time</code></a>
|
||||
</td>
|
||||
<td>
|
||||
<!-- ExpirationTimestamp indicates a time when the provided credentials expire. -->
|
||||
|
@ -331,5 +331,3 @@ exec 插件本身至少应通过文件访问许可来实施保护。</p>
|
|||
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
||||
|
|
|
@ -26,7 +26,7 @@ package: imagepolicy.k8s.io/v1alpha1
|
|||
<tr><td><code>kind</code><br/>string</td><td><code>ImageReview</code></td></tr>
|
||||
|
||||
<tr><td><code>metadata</code><br/>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.27/#objectmeta-v1-meta"><code>meta/v1.ObjectMeta</code></a>
|
||||
<a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.28/#objectmeta-v1-meta"><code>meta/v1.ObjectMeta</code></a>
|
||||
</td>
|
||||
<td>
|
||||
<!--
|
||||
|
@ -207,4 +207,3 @@ appropriate prefix).</p>
|
|||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
|
|
Loading…
Reference in New Issue