Add examples for webhook client auth (#16204)

This commit is contained in:
Jordan Liggitt
2019-09-05 12:13:08 -04:00
committed by Kubernetes Prow Robot
parent 21ee964e3e
commit 19a4832dff
@@ -185,13 +185,38 @@ See the [webhook configuration](#webhook-configuration) section for details abou
apiVersion: v1 apiVersion: v1
kind: Config kind: Config
users: users:
# DNS name of webhook service, i.e., <service name>.<namespace>.svc, or the URL # name should be set to the DNS name of the service or the host (including port) of the URL the webhook is configured to speak to.
# of the webhook server. # If a non-443 port is used for services, it must be included in the name when configuring 1.16+ API servers.
#
# For a webhook configured to speak to a service on the default port (443), specify the DNS name of the service:
# - name: webhook1.ns1.svc
# user: ...
#
# For a webhook configured to speak to a service on non-default port (e.g. 8443), specify the DNS name and port of the service in 1.16+:
# - name: webhook1.ns1.svc:8443
# user: ...
# and optionally create a second stanza using only the DNS name of the service for compatibility with 1.15 API servers:
# - name: webhook1.ns1.svc
# user: ...
#
# For webhooks configured to speak to a URL, match the host (and port) specified in the webhook's URL. Examples:
# A webhook with `url: https://www.example.com`:
# - name: www.example.com
# user: ...
#
# A webhook with `url: https://www.example.com:443`:
# - name: www.example.com:443
# user: ...
#
# A webhook with `url: https://www.example.com:8443`:
# - name: www.example.com:8443
# user: ...
#
- name: 'webhook1.ns1.svc' - name: 'webhook1.ns1.svc'
user: user:
client-certificate-data: <pem encoded certificate> client-certificate-data: <pem encoded certificate>
client-key-data: <pem encoded key> client-key-data: <pem encoded key>
# The `name` supports using * to wildmatch prefixing segments. # The `name` supports using * to wildcard-match prefixing segments.
- name: '*.webhook-company.org' - name: '*.webhook-company.org'
user: user:
password: <password> password: <password>