fixed some grammatical mistakes
This commit is contained in:
@@ -205,7 +205,7 @@ spec:
|
|||||||
```
|
```
|
||||||
|
|
||||||
Service account bearer tokens are perfectly valid to use outside the cluster and
|
Service account bearer tokens are perfectly valid to use outside the cluster and
|
||||||
can be used to create identities for long standing jobs that wish to talk to the
|
can be used to create identities for long-standing jobs that wish to talk to the
|
||||||
Kubernetes API. To manually create a service account, simply use the `kubectl
|
Kubernetes API. To manually create a service account, simply use the `kubectl
|
||||||
create serviceaccount (NAME)` command. This creates a service account in the
|
create serviceaccount (NAME)` command. This creates a service account in the
|
||||||
current namespace and an associated secret.
|
current namespace and an associated secret.
|
||||||
@@ -233,7 +233,7 @@ secrets:
|
|||||||
- name: jenkins-token-1yvwg
|
- name: jenkins-token-1yvwg
|
||||||
```
|
```
|
||||||
|
|
||||||
The created secret holds the public CA of the API server and a signed JSON Web
|
The created secret holds the public CA of the API server, and a signed JSON Web
|
||||||
Token (JWT).
|
Token (JWT).
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
@@ -320,7 +320,7 @@ sequenceDiagram
|
|||||||
8. Once authorized the API server returns a response to `kubectl`
|
8. Once authorized the API server returns a response to `kubectl`
|
||||||
9. `kubectl` provides feedback to the user
|
9. `kubectl` provides feedback to the user
|
||||||
|
|
||||||
Since all of the data needed to validate who you are is in the `id_token`, Kubernetes doesn't need to
|
Since all the data needed to validate who you are is in the `id_token`, Kubernetes doesn't need to
|
||||||
"phone home" to the identity provider. In a model where every request is stateless this provides a very scalable
|
"phone home" to the identity provider. In a model where every request is stateless this provides a very scalable
|
||||||
solution for authentication. It does offer a few challenges:
|
solution for authentication. It does offer a few challenges:
|
||||||
|
|
||||||
@@ -733,7 +733,7 @@ to the impersonated user info.
|
|||||||
The following HTTP headers can be used to performing an impersonation request:
|
The following HTTP headers can be used to performing an impersonation request:
|
||||||
|
|
||||||
* `Impersonate-User`: The username to act as.
|
* `Impersonate-User`: The username to act as.
|
||||||
* `Impersonate-Group`: A group name to act as. Can be provided multiple times to set multiple groups. Optional. Requires "Impersonate-User"
|
* `Impersonate-Group`: A group name to act as. Can be provided multiple times to set multiple groups. Optional. Requires "Impersonate-User".
|
||||||
* `Impersonate-Extra-( extra name )`: A dynamic header used to associate extra fields with the user. Optional. Requires "Impersonate-User". In order to be preserved consistently, `( extra name )` should be lower-case, and any characters which aren't [legal in HTTP header labels](https://tools.ietf.org/html/rfc7230#section-3.2.6) MUST be utf8 and [percent-encoded](https://tools.ietf.org/html/rfc3986#section-2.1).
|
* `Impersonate-Extra-( extra name )`: A dynamic header used to associate extra fields with the user. Optional. Requires "Impersonate-User". In order to be preserved consistently, `( extra name )` should be lower-case, and any characters which aren't [legal in HTTP header labels](https://tools.ietf.org/html/rfc7230#section-3.2.6) MUST be utf8 and [percent-encoded](https://tools.ietf.org/html/rfc3986#section-2.1).
|
||||||
|
|
||||||
{{< note >}}
|
{{< note >}}
|
||||||
|
|||||||
Reference in New Issue
Block a user