Merge pull request #1961 from InQuicker/kubelet-auth-formatting

Fix the formatting of bullet lists on the kubelet auth page.
This commit is contained in:
devin-donnelly
2016-12-21 17:25:42 -05:00
committed by GitHub
@@ -21,14 +21,17 @@ authentication methods are treated as anonymous requests, and given a username o
and a group of `system:unauthenticated`. and a group of `system:unauthenticated`.
To disable anonymous access and send `401 Unauthorized` responses to unauthenticated requests: To disable anonymous access and send `401 Unauthorized` responses to unauthenticated requests:
* start the kubelet with the `--anonymous-auth=false` flag * start the kubelet with the `--anonymous-auth=false` flag
To enable X509 client certificate authentication to the kubelet's HTTPS endpoint: To enable X509 client certificate authentication to the kubelet's HTTPS endpoint:
* start the kubelet with the `--client-ca-file` flag, providing a CA bundle to verify client certificates with * start the kubelet with the `--client-ca-file` flag, providing a CA bundle to verify client certificates with
* start the apiserver with `--kubelet-client-certificate` and `--kubelet-client-key` flags * start the apiserver with `--kubelet-client-certificate` and `--kubelet-client-key` flags
* see the [apiserver authentication documentation](/docs/admin/authentication/#x509-client-certs) for more details * see the [apiserver authentication documentation](/docs/admin/authentication/#x509-client-certs) for more details
To enable API bearer tokens (including service account tokens) to be used to authenticate to the kubelet's HTTPS endpoint: To enable API bearer tokens (including service account tokens) to be used to authenticate to the kubelet's HTTPS endpoint:
* ensure the `authentication.k8s.io/v1beta1` API group is enabled in the API server * ensure the `authentication.k8s.io/v1beta1` API group is enabled in the API server
* start the kubelet with the `--authentication-token-webhook`, `--kubeconfig`, and `--require-kubeconfig` flags * start the kubelet with the `--authentication-token-webhook`, `--kubeconfig`, and `--require-kubeconfig` flags
* the kubelet calls the `TokenReview` API on the configured API server to determine user information from bearer tokens * the kubelet calls the `TokenReview` API on the configured API server to determine user information from bearer tokens
@@ -38,11 +41,13 @@ To enable API bearer tokens (including service account tokens) to be used to aut
Any request that is successfully authenticated (including an anonymous request) is then authorized. The default authorization mode is `AlwaysAllow`, which allows all requests. Any request that is successfully authenticated (including an anonymous request) is then authorized. The default authorization mode is `AlwaysAllow`, which allows all requests.
There are many possible reasons to subdivide access to the kubelet API: There are many possible reasons to subdivide access to the kubelet API:
* anonymous auth is enabled, but anonymous users' ability to call the kubelet API should be limited * anonymous auth is enabled, but anonymous users' ability to call the kubelet API should be limited
* bearer token auth is enabled, but arbitrary API users' (like service accounts) ability to call the kubelet API should be limited * bearer token auth is enabled, but arbitrary API users' (like service accounts) ability to call the kubelet API should be limited
* client certificate auth is enabled, but only some of the client certificates signed by the configured CA should be allowed to use the kubelet API * client certificate auth is enabled, but only some of the client certificates signed by the configured CA should be allowed to use the kubelet API
To subdivide access to the kubelet API, delegate authorization to the API server: To subdivide access to the kubelet API, delegate authorization to the API server:
* ensure the `authorization.k8s.io/v1beta1` API group is enabled in the API server * ensure the `authorization.k8s.io/v1beta1` API group is enabled in the API server
* start the kubelet with the `--authorization-mode=Webhook`, `--kubeconfig`, and `--require-kubeconfig` flags * start the kubelet with the `--authorization-mode=Webhook`, `--kubeconfig`, and `--require-kubeconfig` flags
* the kubelet calls the `SubjectAccessReview` API on the configured API server to determine whether each request is authorized * the kubelet calls the `SubjectAccessReview` API on the configured API server to determine whether each request is authorized
@@ -63,10 +68,10 @@ The resource and subresource is determined from the incoming request's path:
Kubelet API | resource | subresource Kubelet API | resource | subresource
-------------|----------|------------ -------------|----------|------------
/stats/* | nodes | stats /stats/\* | nodes | stats
/metrics/* | nodes | metrics /metrics/\* | nodes | metrics
/logs/* | nodes | log /logs/\* | nodes | log
/spec/* | nodes | spec /spec/\* | nodes | spec
*all others* | nodes | proxy *all others* | nodes | proxy
The namespace and API group attributes are always an empty string, and The namespace and API group attributes are always an empty string, and
@@ -74,8 +79,9 @@ the resource name is always the name of the kubelet's `Node` API object.
When running in this mode, ensure the user identified by the `--kubelet-client-certificate` and `--kubelet-client-key` When running in this mode, ensure the user identified by the `--kubelet-client-certificate` and `--kubelet-client-key`
flags passed to the apiserver is authorized for the following attributes: flags passed to the apiserver is authorized for the following attributes:
* verb=*, resource=nodes, subresource=proxy
* verb=*, resource=nodes, subresource=stats * verb=\*, resource=nodes, subresource=proxy
* verb=*, resource=nodes, subresource=log * verb=\*, resource=nodes, subresource=stats
* verb=*, resource=nodes, subresource=spec * verb=\*, resource=nodes, subresource=log
* verb=*, resource=nodes, subresource=metrics * verb=\*, resource=nodes, subresource=spec
* verb=\*, resource=nodes, subresource=metrics