-
Notifications
You must be signed in to change notification settings - Fork 1.6k
Closed
Labels
kind/api-changeCategorizes issue or PR as related to adding, removing, or otherwise changing an APICategorizes issue or PR as related to adding, removing, or otherwise changing an APIsig/authCategorizes an issue or PR as relevant to SIG Auth.Categorizes an issue or PR as relevant to SIG Auth.stage/stableDenotes an issue tracking an enhancement targeted for Stable/GA statusDenotes an issue tracking an enhancement targeted for Stable/GA statustracked/noDenotes an enhancement issue is NOT actively being tracked by the Release TeamDenotes an enhancement issue is NOT actively being tracked by the Release Team
Milestone
Description
Enhancement Description
- One-line enhancement description (can be used as a release note): Provide OIDC discovery endpoints for the API server's service account token issuer.
- Kubernetes Enhancement Proposal: https://github.com/kubernetes/enhancements/tree/master/keps/sig-auth/1393-oidc-discovery
- Associated Pull Requests:
- Feature, unit and integration tests: Provide OIDC discovery for service account token issuer kubernetes#80724
- Agnhost: Update agnhost to test OIDC validation of JWT tokens kubernetes#88049
- E2E Test: Add e2e test for validating JWTs as OIDC tokens kubernetes#88048
- Docs PR: ServiceAccountIssuerDiscovery: Add user facing documentation website#19328
- Beta PRs:
- kops integration (evidence of use on multiple clouds): Simplified form of IAM Roles for ServiceAccounts kops#9352
- Migrate to Beta: Graduate ServiceAccountIssuerDiscovery to beta kubernetes#91921
- Beta Docs PR: Update docs for ServiceAccountIssuerDiscovery beta website#23887
- GA PRs:
- PRR Updates in KEP: Add PRR survey to OIDC Discovery KEP #2363
- Move E2E test to main E2E suite: Move ServiceAccountIssuerDiscovery test into main e2e suite kubernetes#98587
- Graduate to GA Graduate ServiceAccountIssuerDiscovery to GA kubernetes#98553
- Promote test to conformance: Promote ServiceAccountIssuerDiscovery test to conformance kubernetes#98586
- GA Docs updates: Update ServiceAccountIssuerDiscovery docs for GA website#26660
- Primary contact (assignee): @mtaufen
- Responsible SIGs: sig-auth
- Enhancement target (which target equals to which milestone):
- Alpha release target (1.18)
- Beta release target (1.20)
- Stable release target (1.21)
kikisdeliveryservice and pacoxu
Metadata
Metadata
Labels
kind/api-changeCategorizes issue or PR as related to adding, removing, or otherwise changing an APICategorizes issue or PR as related to adding, removing, or otherwise changing an APIsig/authCategorizes an issue or PR as relevant to SIG Auth.Categorizes an issue or PR as relevant to SIG Auth.stage/stableDenotes an issue tracking an enhancement targeted for Stable/GA statusDenotes an issue tracking an enhancement targeted for Stable/GA statustracked/noDenotes an enhancement issue is NOT actively being tracked by the Release TeamDenotes an enhancement issue is NOT actively being tracked by the Release Team
Type
Projects
Status
Closed / Done