![]() Automatic merge from submit-queue Include system:authenticated group when impersonating Fixes #43227 An authorized impersonation request solely for a specific username previously resulted in a `user.Info` that did not include either the `system:authenticated` or `system:unauthenticated` groups. That meant that permissions intended to be granted to all users, like discovery, would be denied the impersonated user. This allows `kubectl get pods --as=<username>` to work as expected ```release-note API requests using impersonation now include the `system:authenticated` group in the impersonated user automatically. ``` |
||
---|---|---|
.. | ||
src/k8s.io | ||
copy.sh | ||
godeps-json-updater.go | ||
prime-apimachinery.sh | ||
README.md |
This staging/src/k8s.io/client-go directory is the staging area of the client repo. It contains a versioned client, tools built around the client like the reflector, and all the client dependencies. The content will be periodically published to k8s.io/client-go repo.
The staged content is copied from the main repo, i.e., k8s.io/kubernetes, with directory rearrangement and necessary rewritings. To sync the content with the latest code in your local k8s.io/kubernetes, you need to run godep restore
in k8s root directory, then run staging/copy.sh.
vendor/k8s.io/client-go is a symlink pointing to this staging area, so to use the packages in the staging area, you can import it as "vendor/client-go/", as if the client were vendored. The client will be vendored from k8s.io/client-go for real after the test matrix is converted to vendor k8s components.