Merge pull request #98724 from deads2k/prove-overrideability
add test to ensure that user can clear alwaysallowpaths
This commit is contained in:
@@ -142,6 +142,7 @@ func TestAddFlags(t *testing.T) {
|
||||
args := []string{
|
||||
"--address=192.168.4.10",
|
||||
"--allocate-node-cidrs=true",
|
||||
"--authorization-always-allow-paths=", // this proves that we can clear the default
|
||||
"--bind-address=192.168.4.21",
|
||||
"--cert-dir=/a/b/c",
|
||||
"--cloud-config=/cloud-config",
|
||||
@@ -257,7 +258,7 @@ func TestAddFlags(t *testing.T) {
|
||||
ClientTimeout: 10 * time.Second,
|
||||
WebhookRetryBackoff: apiserveroptions.DefaultAuthWebhookRetryBackoff(),
|
||||
RemoteKubeConfigFileOptional: true,
|
||||
AlwaysAllowPaths: []string{"/healthz", "/readyz", "/livez"}, // note: this does not match /healthz/ or /healthz/*
|
||||
AlwaysAllowPaths: []string{},
|
||||
AlwaysAllowGroups: []string{"system:masters"},
|
||||
},
|
||||
Kubeconfig: "/kubeconfig",
|
||||
|
Reference in New Issue
Block a user