From fa44441f680014f96bc0c054102509c4ac1a45cc Mon Sep 17 00:00:00 2001 From: Mike Spreitzer Date: Sun, 25 Sep 2016 15:55:49 -0700 Subject: [PATCH 1/5] Noted HTTP syntax restriction on bearer tokens Noted that every bearer token, in any of the four authentication strategies that use bearer tokens, appears in an HTTP header value without additional quotation/encoding (beyond that supported by HTTP). Included a fully concrete example. Wrote this down once, where the issue first arises, and referenced it from the other relevant strategies. This constraint was elicited in #sig-auth discussion on Sep 21, and not previously stated explicitly and in a way that clearly applied to all four kinds of bearer token --- leaving the reader to wonder if some other encoding is expected. --- docs/admin/authentication.md | 35 ++++++++++++++++++++++------------- 1 file changed, 22 insertions(+), 13 deletions(-) diff --git a/docs/admin/authentication.md b/docs/admin/authentication.md index c3c5e52c77..0be8b50db8 100644 --- a/docs/admin/authentication.md +++ b/docs/admin/authentication.md @@ -66,8 +66,7 @@ See [APPENDIX](#appendix) for how to generate a client cert. ### Static Token File -Token file is enabled by passing the `--token-auth-file=SOMEFILE` option to the -API server. Currently, tokens last indefinitely, and the token list cannot be +The API server reads bearer tokens from a file when given the `--token-auth-file=SOMEFILE` option on the command line. Currently, tokens last indefinitely, and the token list cannot be changed without restarting API server. The token file format is implemented in `plugin/pkg/auth/authenticator/token/tokenfile/...` @@ -78,8 +77,19 @@ optional group names. Note, if you have more than one group the column must be d token,user,uid,"group1,group2,group3" ``` -When using token authentication from an http client the API server expects an `Authorization` -header with a value of `Bearer SOMETOKEN`. +#### Putting a Bearer Token in a Request + +When using bearer token authentication from an http client, the API +server expects an `Authorization` header with a value of `Bearer +THETOKEN`. The bearer token must be a character sequence that can be +put in an HTTP header value using no more than the encoding and +quoting facilities of HTTP. For example: if the bearer token is +`31ada4fd-adec-460c-809a-9e56ceb75269` then it would appear in an HTTP +header as shown below. + +```http +Authentication: Bearer 31ada4fd-adec-460c-809a-9e56ceb75269 +``` ### Static Password File @@ -171,7 +181,8 @@ type: kubernetes.io/service-account-token Note: values are base64 encoded because secrets are always base64 encoded. The signed JWT can be used as a bearer token to authenticate as the given service -account. Normally these secrets are mounted into pods for in-cluster access to +account. See [above](#putting-a-bearer-token-in-a-request) for how the token is included +in a request. Normally these secrets are mounted into pods for in-cluster access to the API server, but can be used from outside the cluster as well. Service accounts authenticate with the username `system:serviceaccount:(NAMESPACE):(SERVICEACCOUNT)`, @@ -192,11 +203,8 @@ email, signed by the server. To identify the user, the authenticator uses the `id_token` (not the `access_token`) from the OAuth2 [token response](https://openid.net/specs/openid-connect-core-1_0.html#TokenResponse) -as a bearer token. - -``` -Authentication: Bearer (id_token) -``` +as a bearer token. See [above](#putting-a-bearer-token-in-a-request) for how the token +is included in a request. To enable the plugin, pass the following required flags: @@ -272,10 +280,11 @@ contexts: name: webhook ``` -When a client attempts to authenticate with the API server using a bearer token, -using the `Authorization: Bearer (TOKEN)` HTTP header the authentication webhook +When a client attempts to authenticate with the API server using a bearer token +as discussed [above](#putting-a-bearer-token-in-a-request), +the authentication webhook queries the remote service with a review object containing the token. Kubernetes -will not challenge request that lack such a header. +will not challenge a request that lacks such a header. Note that webhook API objects are subject to the same [versioning compatibility rules](/docs/api/) as other Kubernetes API objects. Implementers should be aware of looser From c38f1f63e499d7abd0d0ba6661f814c0b0f1f4ac Mon Sep 17 00:00:00 2001 From: Piyush Madan Date: Thu, 29 Sep 2016 01:23:06 -0400 Subject: [PATCH 2/5] minor edit - removed ` in one of the cmds --- docs/getting-started-guides/libvirt-coreos.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/getting-started-guides/libvirt-coreos.md b/docs/getting-started-guides/libvirt-coreos.md index f752a13aee..86b0707092 100644 --- a/docs/getting-started-guides/libvirt-coreos.md +++ b/docs/getting-started-guides/libvirt-coreos.md @@ -134,7 +134,7 @@ export KUBERNETES_PROVIDER=libvirt-coreos; wget -q -O - https://get.k8s.io | bas Here is the curl version of this command: ```shell -export KUBERNETES_PROVIDER=libvirt-coreos; curl -sS https://get.k8s.io | bash` +export KUBERNETES_PROVIDER=libvirt-coreos; curl -sS https://get.k8s.io | bash ``` This script downloads and unpacks the tarball, then spawns a Kubernetes cluster on CoreOS instances with the following characteristics: From 2b2d8dc0bc4d568ad1ad1be8e9834c2e73d7d1e6 Mon Sep 17 00:00:00 2001 From: Tobias Bradtke Date: Thu, 29 Sep 2016 12:23:37 +0200 Subject: [PATCH 3/5] Fix urls --- docs/user-guide/index.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/user-guide/index.md b/docs/user-guide/index.md index 44dd71f41e..70bcb5be6d 100644 --- a/docs/user-guide/index.md +++ b/docs/user-guide/index.md @@ -89,5 +89,5 @@ Pods and containers * [Images and registries](/docs/user-guide/images/) * [Migrating from docker-cli to kubectl](/docs/user-guide/docker-cli-to-kubectl/) * [Configuration Best Practices and Tips](/docs/user-guide/config-best-practices/) - * [Assign pods to selected nodes](https://github.com/kubernetes/kubernetes.github.io/tree/{{page.docsbranch}}/docs/user-guide/node-selection/) - * [Perform a rolling update on a running group of pods](https://github.com/kubernetes/kubernetes.github.io/tree/{{page.docsbranch}}/docs/user-guide/update-demo/) + * [Assign pods to selected nodes](/docs/user-guide/node-selection/) + * [Perform a rolling update on a running group of pods](/docs/user-guide/update-demo/) From a6c95792335ba50de05e5d64264134d8cbc7da6f Mon Sep 17 00:00:00 2001 From: scotty Date: Fri, 30 Sep 2016 10:21:03 -0700 Subject: [PATCH 4/5] partners --- _includes/case-study-styles.html | 76 ++++++++++++++++---------------- _sass/_base.sass | 3 +- _sass/_desktop.sass | 2 +- case-studies/index.html | 2 +- case-studies/pearson.html | 2 +- case-studies/wikimedia.html | 2 +- js/script.js | 3 +- partners/index.html | 60 +++++++++++++++++++++++++ 8 files changed, 106 insertions(+), 44 deletions(-) create mode 100644 partners/index.html diff --git a/_includes/case-study-styles.html b/_includes/case-study-styles.html index 7914ef76ac..48058bd27b 100644 --- a/_includes/case-study-styles.html +++ b/_includes/case-study-styles.html @@ -3,40 +3,40 @@ margin-top: 1em !important; } - #caseStudies p { + .gridPage p { color: rgb(26,26,26) !important; margin-left: 0 !important; padding-left: 0 !important; font-weight: 300 !important; } - #caseStudies #mainContent { + .gridPage #mainContent { padding: 0; } - #caseStudies #mainContent .content { + .gridPage #mainContent .content { padding-top: 0; } - #caseStudies main { + .gridPage main { max-width: 1100px !important; } - #caseStudies .content { + .gridPage .content { position: relative; margin: 0 auto 50px; max-width: 90%; } - #caseStudies .content p { + .gridPage .content p { line-height: 24px !important; } - #caseStudies .content h3 { + .gridPage .content h3 { padding: 0 !important; } - #caseStudies #hero h5 { + .gridPage #hero h5 { padding-left: 20px; margin: 0; } @@ -67,7 +67,7 @@ left: 0; } - #caseStudies #mainContent .content .case-study p { + .gridPage #mainContent .content .case-study p { font-family: "Roboto", sans-serif; font-size: 16px; padding: 0; @@ -77,13 +77,13 @@ font-style: italic; } - #caseStudies #video { + .gridPage #video { background: #f9f9f9; height: auto; /*height: 340px;*/ } - #caseStudies #video main { + .gridPage #video main { position: relative; max-width: 900px !important; height: 100%; @@ -93,19 +93,19 @@ padding: 50px 20px; } - #caseStudies #video main > div { + .gridPage #video main > div { width: 50%; } - #caseStudies #video main #zulilyLogo { + .gridPage #video main #zulilyLogo { width: 100px; } - #caseStudies #video main img { + .gridPage #video main img { max-width: 100%; } - #caseStudies #video h3 { + .gridPage #video h3 { font-size: 32px; font-weight: 300; line-height: 38px; @@ -113,57 +113,57 @@ margin: 0 0 1em 0; } - #caseStudies #video p { + .gridPage #video p { margin: 0; } - #caseStudies #video p.attrib { + .gridPage #video p.attrib { margin-bottom: 20px; } - #caseStudies #video button > h6 { + .gridPage #video button > h6 { font-size: 18px; font-weight: 500; margin: 1em 0; color: #326de6; } - #caseStudies #users { + .gridPage #users { padding: 50px; } - #caseStudies #users main { + .gridPage #users main { max-width: 1150px !important; } - #caseStudies #users main h3 { + .gridPage #users main h3 { padding-left: 20px; margin-bottom: 20px; } - #caseStudies #usersGrid { + .gridPage #usersGrid { position: relative; display: flex; flex-wrap: wrap; justify-content: center; } - #caseStudies #usersGrid a { + .gridPage #usersGrid a { display: inline-block; margin: 5px; } - #caseStudies #usersGrid a img { + .gridPage #usersGrid a img { box-shadow: 1px 1px 2px transparent; transition: box-shadow 0.25s; } - #caseStudies #usersGrid a img:hover { + .gridPage #usersGrid a img:hover { box-shadow: 1px 1px 2px #cccccc; } - #caseStudies #usersGrid a:last-child img, - #caseStudies #usersGrid a:last-child img:hover { + .gridPage #usersGrid a:last-child img, + .gridPage #usersGrid a:last-child img:hover { box-shadow: 1px 1px 2px transparent; } @@ -173,12 +173,12 @@ box-shadow: 1px 2px 2px #dddddd; } - #caseStudies .feature { + .gridPage .feature { position: relative; padding: 20px 0 20px 242px; } - #caseStudies .feature img { + .gridPage .feature img { position: absolute; top: 20px; left: 0; @@ -225,7 +225,7 @@ margin-bottom: 0.5em; } - #caseStudies .feature p.quote { + .gridPage .feature p.quote { font-size: 20px; line-height: 28px !important; } @@ -250,20 +250,20 @@ } @media screen and (max-width: 900px){ - #caseStudies #video main { + .gridPage #video main { flex-direction: column; align-items: center; } - #caseStudies #video main > div { + .gridPage #video main > div { width: 400px; } - #caseStudies #video main > div + div { + .gridPage #video main > div + div { margin-top: 30px; } - #caseStudies #video h3 { + .gridPage #video h3 { max-width: 100%; } } @@ -282,12 +282,12 @@ transform: translateX(-50%); } - #caseStudies .feature { + .gridPage .feature { margin-top: 50px; padding: 180px 0 0; } - #caseStudies .feature img { + .gridPage .feature img { top: 0; left: 50%; transform: translateX(-50%); @@ -295,12 +295,12 @@ } @media screen and (max-width: 480px){ - #caseStudies #hero { + .gridPage #hero { padding-right: 20px; padding-left: 20px; } - #caseStudies #video main > div { + .gridPage #video main > div { width: 80%; min-width: 280px; } diff --git a/_sass/_base.sass b/_sass/_base.sass index 91d47a6b48..a8ac4b47c4 100644 --- a/_sass/_base.sass +++ b/_sass/_base.sass @@ -1131,7 +1131,7 @@ $feature-box-div-margin-bottom: 40px // Community -#community, #caseStudies +#community, .gridPage &.open-nav, &.flip-nav .logo background-image: url(/images/nav_logo2.svg) @@ -1340,3 +1340,4 @@ $feature-box-div-margin-bottom: 40px // // // +// \ No newline at end of file diff --git a/_sass/_desktop.sass b/_sass/_desktop.sass index 7faddf913c..033e998ba0 100644 --- a/_sass/_desktop.sass +++ b/_sass/_desktop.sass @@ -270,7 +270,7 @@ $video-section-height: 550px - #community, #caseStudies + #community, .gridPage #hero text-align: left diff --git a/case-studies/index.html b/case-studies/index.html index 8b0ffea42c..4b92adb805 100644 --- a/case-studies/index.html +++ b/case-studies/index.html @@ -3,7 +3,7 @@ title: Case Studies --- - + {% include head-header.html %}
diff --git a/case-studies/pearson.html b/case-studies/pearson.html index 8625707f11..bf871789b9 100644 --- a/case-studies/pearson.html +++ b/case-studies/pearson.html @@ -3,7 +3,7 @@ title: Pearson Case Study --- - + {% include head-header.html %}
diff --git a/case-studies/wikimedia.html b/case-studies/wikimedia.html index c725ca7683..00eb47e3e0 100644 --- a/case-studies/wikimedia.html +++ b/case-studies/wikimedia.html @@ -3,7 +3,7 @@ title: Wikimedia Case Study --- - + {% include head-header.html %}
diff --git a/js/script.js b/js/script.js index 99574e7f83..22eff0a1b4 100755 --- a/js/script.js +++ b/js/script.js @@ -135,8 +135,9 @@ var kub = (function () { // case 'caseStudies': bodyHeight = windowHeight; break; - + case 'caseStudies': + case 'partners': bodyHeight = windowHeight * 2; break; diff --git a/partners/index.html b/partners/index.html new file mode 100644 index 0000000000..c47f0998a7 --- /dev/null +++ b/partners/index.html @@ -0,0 +1,60 @@ +--- +title: Partners +--- + + + +{% include head-header.html %} + +
+

Kubernetes Partners

+
Growing the Kubernetes ecosystem.
+ +
+ +
+
+
We are working with a broad group of partners who contribute to the Kubernetes core codebase, making it stronger and richer, creating a vibrant Kubernetes ecosystem supporting a spectrum of complementing platforms, from open source solutions to market-leading technologies.
+

ISV Partners

+
+ + + + + + + + + + + + + + + + + + + + +
+
+
+ + +{% include footer.html %} +{% include case-study-styles.html %} + + + From 5eff46b03577eb4f1d6fe6b2da1dc760acbb67e4 Mon Sep 17 00:00:00 2001 From: "Tim St. Clair" Date: Fri, 30 Sep 2016 11:13:07 -0700 Subject: [PATCH 5/5] Fix links to AppArmor policy references --- docs/admin/apparmor/index.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/admin/apparmor/index.md b/docs/admin/apparmor/index.md index 395aba1989..9730c07953 100644 --- a/docs/admin/apparmor/index.md +++ b/docs/admin/apparmor/index.md @@ -349,8 +349,8 @@ logs or through `journalctl`. More information is provided in Additional resources: -- http://wiki.apparmor.net/index.php/QuickProfileLanguage -- http://wiki.apparmor.net/index.php/ProfileLanguage +- [Quick guide to the AppArmor profile language](http://wiki.apparmor.net/index.php/QuickProfileLanguage) +- [AppArmor core policy reference](http://wiki.apparmor.net/index.php/ProfileLanguage) ## API Reference