Merge pull request #1304 from MikeSpreitzer/updoc2

Clarified the apiGroup identified by empty string
This commit is contained in:
devin-donnelly
2016-10-10 15:38:31 -07:00
committed by GitHub
+3 -3
View File
@@ -53,7 +53,7 @@ A request has the following attributes that can be considered for authorization:
- what resource is being accessed (for resource requests only) - what resource is being accessed (for resource requests only)
- what subresource is being accessed (for resource requests only) - what subresource is being accessed (for resource requests only)
- the namespace of the object being accessed (for namespaced resource requests only) - the namespace of the object being accessed (for namespaced resource requests only)
- the API group being accessed (for resource requests only) - the API group being accessed (for resource requests only); an empty string designates the [core API group](../api.md#api-groups)
The request verb for a resource API endpoint can be determined by the HTTP verb used and whether or not the request acts on an individual resource or a collection of resources: The request verb for a resource API endpoint can be determined by the HTTP verb used and whether or not the request acts on an individual resource or a collection of resources:
@@ -231,7 +231,7 @@ metadata:
namespace: default namespace: default
name: pod-reader name: pod-reader
rules: rules:
- apiGroups: [""] # The API group "" indicates the default API Group. - apiGroups: [""] # The API group "" indicates the core API Group.
resources: ["pods"] resources: ["pods"]
verbs: ["get", "watch", "list"] verbs: ["get", "watch", "list"]
nonResourceURLs: [] nonResourceURLs: []
@@ -632,4 +632,4 @@ subjectaccessreview "" created
``` ```
This is useful for debugging access problems, in that you can use this resource This is useful for debugging access problems, in that you can use this resource
to determine what access an authorizer is granting. to determine what access an authorizer is granting.