agent: investigate support for providing kubelet credential plugin with federated identity support
- Dominant language
- Go
- Stars
- 28
- Forks
- 11
- Avg merge
- 1d 8h
- Merged PRs (30d)
- 55
Description
When accessing ACR outside of Azure, we will very likely need a way to exchange image pull token for the kubelet. We could make sure of a special kubelet cred plugin to support exchaing image pull secret using federated identity.
refs:
- https://github.com/kubernetes/enhancements/blob/master/keps/sig-auth/4412-projected-service-account-tokens-for-kubelet-image-credential-providers/README.md
- https://github.com/Azure/msi-acrpull
Contributor guide
Research direction
Start by reading the linked Kubernetes KEP on projected service account tokens for kubelet image credential providers and the Azure/msi-acrpull project. Determine the required approach for exchanging an ACR image pull token for the kubelet through federated identity; done means the support scope and implementation path are established.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- azure, go, kubernetes
- Domain
- authentication, cloud, devops
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100