Commit Graph

2258 Commits

Author SHA1 Message Date
Kubernetes Publisher fb7c01f587 Merge pull request #69551 from fqsghostcloud/master
fix typo

Kubernetes-commit: 66f68f3ccf391b4377b71787827295e8396de45d
2018-11-01 05:19:10 +00:00
Kubernetes Publisher 6bbe65a989 Merge pull request #70453 from liggitt/api-owners
Update API-related owners files

Kubernetes-commit: c81a4a09cf07083265591a9f48c53e80c13d3ebd
2018-11-01 01:16:03 +00:00
Daniel Smith 8d64bed783 update generated deps
Kubernetes-commit: dcb10d81d18f4e8a58496ef61b62247ae93bbaef
2018-10-31 17:11:23 -07:00
Mehdy Bohlool d7da690844 Update generated files
Kubernetes-commit: e27096cdb468ace668f4f333e9acb46daf33df3f
2018-10-31 10:18:07 -07:00
Chao Wang f8fa426bd3 Use `audit.k8s.io/v1` as default value of option --audit-webhook-version and --audit-log-version in release 1.13
Kubernetes-commit: 9671a035f7e7308ac804b4637af19bac2ecce0f4
2018-10-31 17:22:37 +08:00
Kubernetes Publisher 768725318f Merge pull request #70168 from wgliang/update-vendor/coreos-etcd
Update vendor package github.com/coreos/...

Kubernetes-commit: 9e31e6567f03cf5cf0b6ff44222409c510393e93
2018-10-31 05:17:14 +00:00
Kubernetes Publisher 62e94fcc19 Merge pull request #70032 from iamneha/delete_namespaced_job_spec
Fix(bug): make body an optional parameter in [DELETE] /apis/batch/v1/…

Kubernetes-commit: 93d1567c6f5037a3844125d2a5f61b2d1a0e6927
2018-10-30 21:31:37 +00:00
Kubernetes Publisher bcc4ccc10c Merge pull request #69884 from liggitt/self-sign-in-memory
Allow components to generate certificates in-memory

Kubernetes-commit: d196d63c01719b78c96571775fc8c0c2b6eb30a0
2018-10-30 21:30:48 +00:00
Jordan Liggitt 670c0a7eb7 Update API-related owners files
Kubernetes-commit: 8c20bdaf4661f8764c7a7f2e42674aa6a9bf5d70
2018-10-30 17:05:08 -04:00
Mike Danese 0bf5dcd764 remove webhook cache implementation and replace with the token cache
The striped cache used by the token cache is slightly more sophisticated
however the simple cache provides about the same exact behavior. I used
the striped cache rather than the simple cache because:

* It has been used without issue as the primary token cache.
* It preforms better under load.
* It is already exposed in the public API of the token cache package.

Kubernetes-commit: 0ec4d6d396f237ccb3ae0e96922a90600befb83d
2018-10-30 12:41:46 -07:00
Mehdy Bohlool 154485c3be Refactor webhookclientConfig validation of admission and audit registration
Kubernetes-commit: 1587d189cbf27b3c2470cf1fe56e50afbde412b6
2018-10-30 11:57:29 -07:00
Nikhita Raghunath e6d011f6fa Add license header to non-generated proto files
Kubernetes-commit: 6285db6576553e40aacb74579de57a77e19bb434
2018-10-30 22:29:07 +05:30
Mike Danese ae00afc213 patch webhook authenticator to support token review with arbitrary audiences
Kubernetes-commit: effad15ecc373beb46afd2915827247da51f399d
2018-10-29 20:45:10 -07:00
Kubernetes Publisher ee4fe25ec2 Merge pull request #70314 from samdamana/auth-revert
Revert "limit forbidden error to details of what was forbidden"

Kubernetes-commit: 361f8c31bd1851a37953e8001d31c20b91a5a24a
2018-10-30 01:28:59 +00:00
Kubernetes Publisher 6b272fc5ca Merge pull request #70310 from mikedanese/trev10
echo audiences in anonymous and insecure authenticators

Kubernetes-commit: 952e7b07c6bbcd27474adde57d4df6a1b15f1db2
2018-10-30 01:27:41 +00:00
qingsenLi 1e20513561 fix typo and instead of amd
Kubernetes-commit: 3e83f0f08abab4c10dfab7053529709883c9b834
2018-10-30 01:27:50 +08:00
Kubernetes Publisher 7ba8fae5dc Merge pull request #69756 from cheftako/trace
Added tracing for long running requests.

Kubernetes-commit: 833dcc2be383cd11933fd0abf74574eb213df59e
2018-10-29 09:35:45 +00:00
Mike Danese 81c2dfc933 make oidc authenticator (more?) audience aware
Part of https://github.com/kubernetes/kubernetes/issues/69893

Kubernetes-commit: a714d9cd044aab9c6f2d11c5bac0c6e60d3ba0b4
2018-10-26 17:46:32 -07:00
Samuel Davidson d8ee4bc0cb Revert "limit forbidden error to details of what was forbidden"
This reverts commit ecbd0137957b4afd4cdd94c0209998228fd70e99.

Kubernetes-commit: 294e02ed4b341fe9497cdfadb93cf19f1e64243f
2018-10-26 15:58:09 -07:00
Mike Danese 7c1e7ec029 echo audiences in anonymous and insecure authenticators
part of https://github.com/kubernetes/kubernetes/issues/69893

Kubernetes-commit: f94bc6193e1e299b1cb258b59504fab81cf8da1c
2018-10-26 15:29:55 -07:00
Neha Yadav 3e6dd50d69 fix(bug): make body a optional parameter in [DELETE] /apis/batch/v1/namespaces/{namespace}/jobs/{name}
Kubernetes-commit: 31372f16129b3f6fa50e85e175643b3a43ba3da2
2018-10-27 00:40:10 +05:30
Kubernetes Publisher e3d7726491 Merge pull request #69389 from smarterclayton/wait_error
kubectl wait must handle errors returned by watch

Kubernetes-commit: b6fd5d93b2048ae19cbcf21bafdd5cd7249d1f33
2018-10-26 15:07:21 +00:00
Kubernetes Publisher 1a3bbcfc1f Merge pull request #70237 from nikhita/proto-remove-trailing-whitespace
Remove trailing whitespace in the protobuf generator

Kubernetes-commit: f4bf0e8d33328183b36e861731f0b01d46ae5833
2018-10-25 08:25:06 -07:00
Kubernetes Publisher 721817c2cf Merge pull request #70087 from liggitt/fix-crd-internal-types
Fix custom resource handler in-memory version

Kubernetes-commit: ed39bd45f531d17d26869aae29f069173cb0ce55
2018-10-26 15:06:18 +00:00
Kubernetes Publisher 62c5b3b954 Merge pull request #69013 from ibrasho-forks/switch-to-http.Error
Update usages of http.ResponseWriter.WriteHeader to use http.Error

Kubernetes-commit: dad07683b101dfa71444d0c580579035fe5cd5a0
2018-10-26 15:06:17 +00:00
Kubernetes Publisher af5573895c Merge pull request #69730 from xichengliudui/fix18101204
Fix some typo

Kubernetes-commit: e77e8ffbf5c466f232f970ae529d745ae27e0ff7
2018-10-26 15:06:17 +00:00
Kubernetes Publisher 64b085417d Merge pull request #69582 from mikedanese/trev7
tokenreview: authenticator interface changes

Kubernetes-commit: baa8d800adce511c5af38dc6a711bd73e38d8046
2018-10-26 15:06:16 +00:00
Kubernetes Publisher 7aa37fef51 Merge pull request #70060 from pbarker/audit-webhook
updates shared apiserver webhook client

Kubernetes-commit: 9fb4a2aa9a553282f8b41ec6ca9d3f8511c660fa
2018-10-26 15:06:15 +00:00
Kubernetes Publisher 99a76d773c Merge pull request #69866 from xichengliudui/fix181016
Remove duplicate words

Kubernetes-commit: 1af393d58ef982056e479ae0a5b33f810d46a375
2018-10-26 15:06:15 +00:00
Kubernetes Publisher decf83a196 Merge pull request #69895 from jpbetz/webhook-metrics-cardinality-fix
Reduce cardinality of admission webhook metrics

Kubernetes-commit: 04d394904846a298af1d37e7a9c15c00f574b09a
2018-10-26 15:06:14 +00:00
Nikhita Raghunath a14ca1235c generated proto: remove trailing whitespace
Kubernetes-commit: e60b0a129a16fbc785c73dd4839acaabf856851c
2018-10-25 16:37:33 +05:30
Patrick Barker e78fc074c8 adds dynamic audit plugins generated
Kubernetes-commit: 54fd930d0e74635fc2a8318cc79d1b055d252d44
2018-10-25 02:43:55 +00:00
Guoliang Wang 8e309ce8e0 Update vendor package github.com/coreos/...
Kubernetes-commit: d462e1e8d7e45894bf2abb7dc5d939f1bd3cae68
2018-10-24 05:43:42 +00:00
Jordan Liggitt dba666528b Allow specifying the hub group-version for a handler
Kubernetes-commit: 0e9b06df0f21b421ff69fd455d4542883d61e8c3
2018-10-22 10:14:52 -04:00
Jordan Liggitt b758170bd7 Inline patch#toUnversioned
Kubernetes-commit: 870d121d5e8033a72c62ef3a64939f0eacab6798
2018-10-22 10:01:27 -04:00
Patrick Barker 53adc37659 updates shared apiserver webhook client
Kubernetes-commit: 5874a1f8faab92aacc5503aa6dbf1c6a724f832f
2018-10-21 10:03:28 -05:00
Patrick Barker 9fd62b6f47 adds dynamic audit configuration
Kubernetes-commit: eb89d3dddd3792b0a6cd724e64bbbc11d6c15380
2018-10-18 21:34:17 -05:00
Patrick Barker f3b69c3f89 adds dynamic audit plugins
Kubernetes-commit: 8eb2150689159bd011aec189cf77e5b15fbcb22b
2018-10-18 21:34:02 -05:00
Mikhail Mazurskiy 3ee5383cc2 Update a few dependencies
github.com/go-openapi/*
github.com/asaskevich/govalidator

Kubernetes-commit: 8763223ab947fa8bae7b3459f70b7094bdc25e1a
2018-10-18 23:33:10 +11:00
Kubernetes Publisher 7f6c545c2e Merge pull request #67547 from pbarker/audit-api
dynamic audit configuration api

Kubernetes-commit: 0652e098d03197aa4cc0a53440f62e425bf992c5
2018-10-18 01:45:35 +00:00
Kubernetes Publisher cfcdd79ca6 Merge pull request #69838 from mikedanese/testonly
make tokentest available to tests only

Kubernetes-commit: 688550b2d34b20474f98c0c967bd846042141182
2018-10-17 17:45:26 +00:00
Kubernetes Publisher 0deca6c827 Merge pull request #69914 from mikedanese/trev8
add some helpers to Audiences to find intersecting audiences

Kubernetes-commit: 399cade80648fb6cf62a65cf92a61adc92f796ec
2018-10-17 09:45:42 +00:00
Mike Danese 89bdd8bce5 create audience unaware authenticator wrappers
Kubernetes-commit: c704d70d49bb9799674d84aecb2a49afb6512e11
2018-10-16 20:57:37 -07:00
Mike Danese 1692373df9 move audience context functions to authenticator package
Kubernetes-commit: 817cf70191b73d1ee9f4e7af83089e5854e5131d
2018-10-31 14:50:11 -07:00
Mike Danese adddd63698 add some helpers to Audiences to find intersecting audiences
Kubernetes-commit: 01ce5bb8a470280d1a8ce68d5b2b4f1b2ac283cf
2018-10-16 20:01:58 -07:00
Patrick Barker 3039935d60 adds dynamic audit integration test
Kubernetes-commit: d995047366153d86f0061b829ee4e7657f17996b
2018-10-16 16:17:33 -06:00
Jordan Liggitt 22df332aff Allow components to generate certificates in-memory
Kubernetes-commit: b7160d4ee2073f06293d7c3b20acdf4620fadf61
2018-10-16 17:22:13 -04:00
Joe Betz 7b71273ec8 Reduce cardinality of admission webhook metrics
Kubernetes-commit: 96034014f5fe08d7bb8b92b8f1679d9761c3f83d
2018-10-16 13:35:42 -07:00
Mike Danese 908a04653f make token cache include audience in hash key
Kubernetes-commit: 809f278b032103cd24fcbb5ea2196c6c7caa6f63
2018-10-16 10:02:01 -07:00
Kubernetes Publisher c53cd379d4 Merge pull request #69842 from liggitt/etcd2-cleanup
etcd2 code cleanup, remove deserialization cache

Kubernetes-commit: 21cb721ca2858a59f0ecbb8fcc6c1807a154a21d
2018-10-16 09:45:14 +00:00