kubernetes/plugin/pkg/admission
Kubernetes Submit Queue 513e67ac02
Merge pull request #55019 from mikedanese/svcacct
Automatic merge from submit-queue (batch tested with PRs 59365, 60446, 60448, 55019, 60431). If you want to cherry-pick this change to another branch, please follow the instructions <a href="https://github.com/kubernetes/community/blob/master/contributors/devel/cherry-picks.md">here</a>.

auth: allow nodes to create tokens for svcaccts of pods

ref https://github.com/kubernetes/kubernetes/issues/58790

running on them. nodes essentially have the power to do this today
but not explicitly. this allows agents using the node identity to
take actions on behalf of local pods.

@kubernetes/sig-auth-pr-reviews @smarterclayton 

```release-note
The node authorizer now allows nodes to request service account tokens for the service accounts of pods running on them.
```
2018-02-27 10:50:46 -08:00
..
admit Autogenerated: hack/update-bazel.sh 2018-02-16 13:43:01 -08:00
alwayspullimages Autogenerated: hack/update-bazel.sh 2018-02-16 13:43:01 -08:00
antiaffinity Autogenerated: hack/update-bazel.sh 2018-02-16 13:43:01 -08:00
defaulttolerationseconds Autogenerated: hack/update-bazel.sh 2018-02-16 13:43:01 -08:00
deny Autogenerated: hack/update-bazel.sh 2018-02-16 13:43:01 -08:00
eventratelimit Run hack/update-all.sh 2018-02-26 17:16:14 -08:00
exec Autogenerated: hack/update-bazel.sh 2018-02-16 13:43:01 -08:00
extendedresourcetoleration Autogenerated: hack/update-bazel.sh 2018-02-16 13:43:01 -08:00
gc Autogenerated: hack/update-bazel.sh 2018-02-16 13:43:01 -08:00
imagepolicy Autogenerated: hack/update-bazel.sh 2018-02-16 13:43:01 -08:00
initialresources Autogenerated: hack/update-bazel.sh 2018-02-16 13:43:01 -08:00
limitranger Autogenerated: hack/update-bazel.sh 2018-02-16 13:43:01 -08:00
namespace Autogenerated: hack/update-bazel.sh 2018-02-16 13:43:01 -08:00
noderestriction noderestriction: restrict nodes TokenRequest permission 2018-02-26 13:46:19 -08:00
persistentvolume Autogenerated: hack/update-bazel.sh 2018-02-16 13:43:01 -08:00
podnodeselector Autogenerated: hack/update-bazel.sh 2018-02-16 13:43:01 -08:00
podpreset Autogenerated: hack/update-bazel.sh 2018-02-16 13:43:01 -08:00
podtolerationrestriction Run hack/update-all.sh 2018-02-26 17:16:14 -08:00
priority remove default priority cache in Priority admission controller 2018-02-26 11:51:45 +08:00
resourcequota Run hack/update-all.sh 2018-02-26 17:16:14 -08:00
security Run hack/update-bazel.sh 2018-02-22 19:23:02 +01:00
securitycontext/scdeny Autogenerated: hack/update-bazel.sh 2018-02-16 13:43:01 -08:00
serviceaccount Autogenerated: hack/update-bazel.sh 2018-02-16 13:43:01 -08:00
storage fix references 2018-02-24 19:16:51 +08:00
OWNERS add deads to admission owners 2017-10-16 13:43:54 -04:00