kubernetes / kubernetes/website

Document role / access mechanism for aggregated API server leases

Open
#38,474 2 comments 0 reactions 0 assignees View on GitHub
kind/feature language/en lifecycle/frozen needs-triage sig/api-machinery
Dominant language
HTML
Stars
5.4k
Forks
15.7k
Avg merge
4d 18h
Merged PRs (30d)
204

Description

**This is a Feature Request**

**What would you like to be added**
Document what Role (and RoleBinding?) you should create so that an aggregated API server can write Leases to the appropriate namespace.
Optionally, also specify generic access - in case your implementation of Kubernetes doesn't include the RBAC APIs.

**Why is this needed**
According to https://github.com/kubernetes/kubernetes/issues/114314#issuecomment-1352079089
> There should be a Role defined to manged identities that any aggregated apiserver can bind to for their own system namespaces

**Comments**
/language en
/kind feature
/sig api-machinery
/lifecycle frozen
/triage accepted

Contributor guide

Open the contributing guide

Research direction

Start with the referenced Kubernetes issue 114314 and review existing documentation about aggregated API server leases, Roles, and RoleBindings. Document the required access for writing Leases in the appropriate namespace, including the optional generic-access guidance if supported by the project; done means an aggregated API server operator can follow the instructions.

Written by the indexing model from the issue text.

Assessment

Tech stack
kubernetes
Domain
api, authorization, documentation
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.