diff --git a/content/en/docs/reference/_index.md b/content/en/docs/reference/_index.md index 1a9f35b2d2..021d2f840d 100644 --- a/content/en/docs/reference/_index.md +++ b/content/en/docs/reference/_index.md @@ -66,6 +66,7 @@ client libraries: * List of [ports and protocols](/docs/reference/ports-and-protocols/) that should be open on control plane and worker nodes + ## Config APIs This section hosts the documentation for "unpublished" APIs which are used to @@ -73,12 +74,12 @@ configure kubernetes components or tools. Most of these APIs are not exposed by the API server in a RESTful way though they are essential for a user or an operator to use or manage a cluster. - * [kube-apiserver configuration (v1alpha1)](/docs/reference/config-api/apiserver-config.v1alpha1/) * [kube-apiserver configuration (v1)](/docs/reference/config-api/apiserver-config.v1/) * [kube-apiserver encryption (v1)](/docs/reference/config-api/apiserver-encryption.v1/) * [kubelet configuration (v1alpha1)](/docs/reference/config-api/kubelet-config.v1alpha1/) and [kubelet configuration (v1beta1)](/docs/reference/config-api/kubelet-config.v1beta1/) +* [kubelet credential providers (v1alpha1)](/docs/reference/config-api/kubelet-credentialprovider.v1alpha1/) * [kube-scheduler configuration (v1beta2)](/docs/reference/config-api/kube-scheduler-config.v1beta2/) and [kube-scheduler configuration (v1beta3)](/docs/reference/config-api/kube-scheduler-config.v1beta3/) * [kube-proxy configuration (v1alpha1)](/docs/reference/config-api/kube-proxy-config.v1alpha1/) diff --git a/content/en/docs/reference/config-api/kubelet-credentialprovider.v1alpha1.md b/content/en/docs/reference/config-api/kubelet-credentialprovider.v1alpha1.md new file mode 100644 index 0000000000..070fe96d09 --- /dev/null +++ b/content/en/docs/reference/config-api/kubelet-credentialprovider.v1alpha1.md @@ -0,0 +1,192 @@ +--- +title: Kubelet CredentialProvider (v1alpha1) +content_type: tool-reference +package: credentialprovider.kubelet.k8s.io/v1alpha1 +auto_generated: true +--- + + +## Resource Types + + +- [CredentialProviderRequest](#credentialprovider-kubelet-k8s-io-v1alpha1-CredentialProviderRequest) +- [CredentialProviderResponse](#credentialprovider-kubelet-k8s-io-v1alpha1-CredentialProviderResponse) + + + + +## `CredentialProviderRequest` {#credentialprovider-kubelet-k8s-io-v1alpha1-CredentialProviderRequest} + + + + + +CredentialProviderRequest includes the image that the kubelet requires authentication for. +Kubelet will pass this request object to the plugin via stdin. In general, plugins should +prefer responding with the same apiVersion they were sent. + +
| Field | Description |
|---|---|
apiVersionstring | credentialprovider.kubelet.k8s.io/v1alpha1 |
kindstring | CredentialProviderRequest |
image [Required]+ string
+ |
++ image is the container image that is being pulled as part of the +credential provider plugin request. Plugins may optionally parse the image +to extract any information required to fetch credentials. | +
| Field | Description |
|---|---|
apiVersionstring | credentialprovider.kubelet.k8s.io/v1alpha1 |
kindstring | CredentialProviderResponse |
cacheKeyType [Required]+ PluginCacheKeyType
+ |
++ cacheKeyType indiciates the type of caching key to use based on the image provided +in the request. There are three valid values for the cache key type: Image, Registry, and +Global. If an invalid value is specified, the response will NOT be used by the kubelet. | +
cacheDuration+ meta/v1.Duration
+ |
++ cacheDuration indicates the duration the provided credentials should be cached for. +The kubelet will use this field to set the in-memory cache duration for credentials +in the AuthConfig. If null, the kubelet will use defaultCacheDuration provided in +CredentialProviderConfig. If set to 0, the kubelet will not cache the provided AuthConfig. | +
auth+ map[string]k8s.io/kubelet/pkg/apis/credentialprovider/v1alpha1.AuthConfig
+ |
++ auth is a map containing authentication information passed into the kubelet. +Each key is a match image string (more on this below). The corresponding authConfig value +should be valid for all images that match against this key. A plugin should set +this field to null if no valid credentials can be returned for the requested image. + +Each key in the map is a pattern which can optionally contain a port and a path. +Globs can be used in the domain, but not in the port or the path. Globs are supported +as subdomains like '∗.k8s.io' or 'k8s.∗.io', and top-level-domains such as 'k8s.∗'. +Matching partial subdomains like 'app∗.k8s.io' is also supported. Each glob can only match +a single subdomain segment, so ∗.io does not match ∗.k8s.io. + +The kubelet will match images against the key when all of the below are true: +- Both contain the same number of domain parts and each part matches. +- The URL path of an imageMatch must be a prefix of the target image URL path. +- If the imageMatch contains a port, then the port must match in the image as well. + +When multiple keys are returned, the kubelet will traverse all keys in reverse order so that: +- longer keys come before shorter keys with the same prefix +- non-wildcard keys come before wildcard keys with the same prefix. + +For any given match, the kubelet will attempt an image pull with the provided credentials, +stopping after the first successfully authenticated pull. + +Example keys: + - 123456789.dkr.ecr.us-east-1.amazonaws.com + - ∗.azurecr.io + - gcr.io + - ∗.∗.registry.io + - registry.io:8080/path | +
| Field | Description |
|---|---|
username [Required]+ string
+ |
++ username is the username used for authenticating to the container registry +An empty username is valid. | +
password [Required]+ string
+ |
++ password is the password used for authenticating to the container registry +An empty password is valid. | +