-
Notifications
You must be signed in to change notification settings - Fork 461
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
🛡 Enable ServiceAccount
token projection and token requestor for provider-local
#5193
Conversation
Skipping CI for Draft Pull Request. |
f0a3483
to
05bfedc
Compare
The extension itself will be adapted separately with gardener#5193
05bfedc
to
95a0395
Compare
The extension itself will be adapted separately with gardener#5193
… library for elimination of static credentials (#5163) * Adapt generic `Worker` actuator for TokenRequestor * Adapt generic `Worker` actuator for projected token mount * Adapt generic `ControlPlane` actuator for TokenRequestor * Adapt `terraformer` library for projected token mount * Please compiler in provider-local package The extension itself will be adapted separately with #5193 * Address PR review feedback
@rfranzke You need rebase this pull request with latest master branch. Please check. |
95a0395
to
11a7175
Compare
/ready |
/assign |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/lgtm
Also tested it, works like a charm 🙂
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Nice, I like it!
/lgtm
… library for elimination of static credentials (gardener#5163) * Adapt generic `Worker` actuator for TokenRequestor * Adapt generic `Worker` actuator for projected token mount * Adapt generic `ControlPlane` actuator for TokenRequestor * Adapt `terraformer` library for projected token mount * Please compiler in provider-local package The extension itself will be adapted separately with gardener#5193 * Address PR review feedback
… library for elimination of static credentials (gardener#5163) * Adapt generic `Worker` actuator for TokenRequestor * Adapt generic `Worker` actuator for projected token mount * Adapt generic `ControlPlane` actuator for TokenRequestor * Adapt `terraformer` library for projected token mount * Please compiler in provider-local package The extension itself will be adapted separately with gardener#5193 * Address PR review feedback
How to categorize this PR?
/area security
/kind enhancement
/merge squash
What this PR does / why we need it:
provider-local
extension is running on a seed with a gardenlet of at leastv1.37
thenServiceAccount
token projection is enabled.machine-controller-manager
deployed into shoot namespacesServiceAccount
token projection.Which issue(s) this PR fixes:
Part of #4659
Part of #4878
Special notes for your reviewer:
✅
Depends on #5162, hence, PR is in draft state.✅
Depends on #5163, hence PR is in draft state.Release note: