Trivial: Make the authentication doc consistent (#9472)
On the content, user categories are defined as service account and normal user. However regular user is written at one place instead of normal user. This replaces the regular user with normal user for the consistency. The option --authentication-token-webhook-config-file is for specifying the configuration file which uses the kubeconfig file format, so this replaces kubeconfig with configuration for avoiding confusions. The last change is updating the order of 'clusters' and 'users' for fitting the following example to read easily.
This commit is contained in:
committed by
k8s-ci-robot
parent
c0af4f7a4a
commit
76b7f9cb1a
@@ -23,7 +23,7 @@ by Kubernetes, and normal users.
|
||||
Normal users are assumed to be managed by an outside, independent service. An
|
||||
admin distributing private keys, a user store like Keystone or Google Accounts,
|
||||
even a file with a list of usernames and passwords. In this regard, _Kubernetes
|
||||
does not have objects which represent normal user accounts._ Regular users
|
||||
does not have objects which represent normal user accounts._ Normal users
|
||||
cannot be added to a cluster through an API call.
|
||||
|
||||
In contrast, service accounts are users managed by the Kubernetes API. They are
|
||||
@@ -400,12 +400,12 @@ kubectl --token=eyJhbGciOiJSUzI1NiJ9.eyJpc3MiOiJodHRwczovL21sYi50cmVtb2xvLmxhbjo
|
||||
|
||||
Webhook authentication is a hook for verifying bearer tokens.
|
||||
|
||||
* `--authentication-token-webhook-config-file` a kubeconfig file describing how to access the remote webhook service.
|
||||
* `--authentication-token-webhook-config-file` a configuration file describing how to access the remote webhook service.
|
||||
* `--authentication-token-webhook-cache-ttl` how long to cache authentication decisions. Defaults to two minutes.
|
||||
|
||||
The configuration file uses the [kubeconfig](/docs/concepts/cluster-administration/authenticate-across-clusters-kubeconfig/)
|
||||
file format. Within the file `users` refers to the API server webhook and
|
||||
`clusters` refers to the remote service. An example would be:
|
||||
file format. Within the file, `clusters` refers to the remote service and
|
||||
`users` refers to the API server webhook. An example would be:
|
||||
|
||||
```yaml
|
||||
# clusters refers to the remote service.
|
||||
|
||||
Reference in New Issue
Block a user