mirror of
https://github.com/k3s-io/kubernetes.git
synced 2025-07-29 14:37:00 +00:00
if we have a dedicated serviceaccount keypair, use it to verify serviceaccounts
This commit is contained in:
parent
c2f3c483a1
commit
ffcbe213c1
@ -1004,6 +1004,9 @@ function start-kube-apiserver {
|
||||
params+=" --kubelet-client-certificate=${APISERVER_CLIENT_CERT_PATH}"
|
||||
params+=" --kubelet-client-key=${APISERVER_CLIENT_KEY_PATH}"
|
||||
fi
|
||||
if [[ -n "${SERVICEACCOUNT_CERT_PATH:-}" ]]; then
|
||||
params+=" --service-account-key-file=${SERVICEACCOUNT_CERT_PATH}"
|
||||
fi
|
||||
params+=" --token-auth-file=/etc/srv/kubernetes/known_tokens.csv"
|
||||
if [[ -n "${KUBE_PASSWORD:-}" && -n "${KUBE_USER:-}" ]]; then
|
||||
params+=" --basic-auth-file=/etc/srv/kubernetes/basic_auth.csv"
|
||||
|
Loading…
Reference in New Issue
Block a user