Add description about BoundServiceAccountTokenVolume feature in serviceaccount admission controller (#11643)

* Add description about BoundServiceAccountTokenVolume feature in serviceaccount admission controller

* Update service-accounts-admin.md

* Update service-accounts-admin.md
This commit is contained in:
WanLinghao
2018-12-17 12:42:45 +08:00
committed by Kubernetes Prow Robot
parent 5f7300c5fe
commit a213182b10
@@ -59,6 +59,10 @@ It acts synchronously to modify pods as they are created or updated. When this p
1. It adds a `volume` to the pod which contains a token for API access.
1. It adds a `volumeSource` to each container of the pod mounted at `/var/run/secrets/kubernetes.io/serviceaccount`.
Starting from v1.13, you can migrate a service account volume to a projected volume when
the `BoundServiceAccountTokenVolume` feature gate is enabled.
The service account token will expire after 1 hour or the pod is deleted. See more details about [projected volume](docs/tasks/configure-pod-container/configure-service-account/#service-account-token-volume-projection).
### Token Controller
TokenController runs as part of controller-manager. It acts asynchronously. It: