kubernetes / kubernetes/website
Document role / access mechanism for aggregated API server leases
- Dominant language
- HTML
- Stars
- 5.4k
- Forks
- 15.7k
- Avg merge
- 4d 18h
- Merged PRs (30d)
- 204
Description
**This is a Feature Request**
**What would you like to be added**
Document what Role (and RoleBinding?) you should create so that an aggregated API server can write Leases to the appropriate namespace.
Optionally, also specify generic access - in case your implementation of Kubernetes doesn't include the RBAC APIs.
**Why is this needed**
According to https://github.com/kubernetes/kubernetes/issues/114314#issuecomment-1352079089
> There should be a Role defined to manged identities that any aggregated apiserver can bind to for their own system namespaces
**Comments**
/language en
/kind feature
/sig api-machinery
/lifecycle frozen
/triage accepted
Contributor guide
Research direction
Start with the referenced Kubernetes issue 114314 and review existing documentation about aggregated API server leases, Roles, and RoleBindings. Document the required access for writing Leases in the appropriate namespace, including the optional generic-access guidance if supported by the project; done means an aggregated API server operator can follow the instructions.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- kubernetes
- Domain
- api, authorization, documentation
- Issue type
- Documentation
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100