kops/cmd
Justin SB c67f895226 Perform challenge callbacks into a node
In order to verify that the caller is running on the specified node,
we source the expected IP address from the cloud, and require that the
node set up a simple challenge/response server to answer requests.

Because the challenge server runs on a port outside of the nodePort
range, this also makes it harder for pods to impersonate their host
nodes - though we do combine this with TPM and similar functionality
where it is available.
2023-05-06 08:03:21 -04:00
..
kops unique instance names to comply with CCM 2023-04-25 16:01:42 +02:00
kops-controller Perform challenge callbacks into a node 2023-05-06 08:03:21 -04:00
kube-apiserver-healthcheck Remove bazel files from vendor 2022-04-12 13:29:03 +02:00
nodeup Remove nodeup's unused cloudinit target 2022-12-20 07:14:15 -08:00