Тёмный

Kubernetes Security - RBAC | Don't let people run loose with admin permissions on your cluster 

Drewbernetes
Подписаться 391
Просмотров 117
50% 1

Опубликовано:

 

14 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 3   
@simo47768
@simo47768 Год назад
Please do oidc and federation service please.
@Drewbernetes
@Drewbernetes Год назад
Hi! I shall be doing soon™ I want to get the security sections done and then I'll be moving onto admission controllers and probes. Once done, OIDC is next - maybe 5/6 videos away. I'll likely be using something like KeyCloak for the OIDC provider. As for federation - I'm still deciding what path to go down for this. When I started making my list of videos I would do this year at the back end of 2022, I intended to do a video on kubefed to cover federation. The problem is that project was archived in April 2023 and with it being no longer maintained, it didn't seem right for me to do a video on that. More here: groups.google.com/g/kubernetes-sig-multicluster/c/lciAVj-_ShE?pli=1 I'm looking into alternatives, the most viable of which seems to be Karmada - karmada.io/docs/ This isn't kuberentes-sigs project like kubefed, but it is inspired by the federation and kubefed projects. It is also part of the CNCF sandbox right now which gives me hope that it could be a good alternative. All that being said, I'll need time on that to figure out how it works before putting anything together for it. But I will be doing a video on federation asap.
@simo47768
@simo47768 Год назад
​@@Drewbernetes My colleague used kubelogin with keycloack (oidc). He can login using two ways. Browser redirect or directly providing password to command line. He wants to use now federation without browser redirect. Just login to k8a with username password as argument. . Now from linux you get a message that you need to redirect browser Do you think this is possible.? He wants to use AD account for automation. Not service token. As tokens are not bound to a person and can be shared . Great content. Soon i will do cks :)
Далее
RBAC in Kubernetes
20:27
Просмотров 35 тыс.
Слушали бы такое на повторе?
01:00
Kubernetes RBAC Explained
23:17
Просмотров 12 тыс.
Trying to get McCLIM to work on WSL
2:03:01
Kubernetes RBAC full tutorial with examples
30:32
Просмотров 12 тыс.
Understanding KUBECTL - Learning Kubernetes
40:34
Просмотров 10 тыс.
Lesson 3 Java Application Server
2:19:55
Просмотров 28