Azure / Azure/unbounded

agent: investigate support for providing kubelet credential plugin with federated identity support

Open
#470 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
28
Forks
11
Avg merge
1d 8h
Merged PRs (30d)
55

Description

When accessing ACR outside of Azure, we will very likely need a way to exchange image pull token for the kubelet. We could make sure of a special kubelet cred plugin to support exchaing image pull secret using federated identity.

refs:

- https://github.com/kubernetes/enhancements/blob/master/keps/sig-auth/4412-projected-service-account-tokens-for-kubelet-image-credential-providers/README.md
- https://github.com/Azure/msi-acrpull

Contributor guide

Open the contributing guide

Research direction

Start by reading the linked Kubernetes KEP on projected service account tokens for kubelet image credential providers and the Azure/msi-acrpull project. Determine the required approach for exchanging an ACR image pull token for the kubelet through federated identity; done means the support scope and implementation path are established.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure, go, kubernetes
Domain
authentication, cloud, devops
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.