Production-Grade Container Scheduling and Management
Go to file
Charles Eckman 5a176ac772 Provide OIDC discovery endpoints
- Add handlers for service account issuer metadata.
- Add option to manually override JWKS URI.
- Add unit and integration tests.
- Add a separate ServiceAccountIssuerDiscovery feature gate.

Additional notes:
- If not explicitly overridden, the JWKS URI will be based on
  the API server's external address and port.

- The metadata server is configured with the validating key set rather
than the signing key set. This allows for key rotation because tokens
can still be validated by the keys exposed in the JWKs URL, even if the
signing key has been rotated (note this may still be a short window if
tokens have short lifetimes).

- The trust model of OIDC discovery requires that the relying party
fetch the issuer metadata via HTTPS; the trust of the issuer metadata
comes from the server presenting a TLS certificate with a trust chain
back to the from the relying party's root(s) of trust. For tests, we use
a local issuer (https://kubernetes.default.svc) for the certificate
so that workloads within the cluster can authenticate it when fetching
OIDC metadata. An API server cannot validly claim https://kubernetes.io,
but within the cluster, it is the authority for kubernetes.default.svc,
according to the in-cluster config.

Co-authored-by: Michael Taufen <mtaufen@google.com>
2020-02-11 16:23:31 -08:00
.github Add kind/flake issue template 2019-12-09 16:06:17 -08:00
api Drop k8s.io/node-api packages 2020-02-07 10:07:14 -05:00
build tolerate when bazel shutdown errors out 2020-02-08 21:47:12 -05:00
CHANGELOG CHANGELOG: Collapse README.md headings in single list 2020-02-06 03:54:10 -05:00
cluster Ability to override versions of containerd/runc 2020-02-08 20:20:15 -05:00
cmd Provide OIDC discovery endpoints 2020-02-11 16:23:31 -08:00
docs Updated OWNERS files to include link to docs 2019-02-04 22:33:12 +01:00
Godeps Bump dependency opencontainers/runc@v1.0.0-rc10 2020-01-24 13:11:01 +01:00
hack Merge pull request #80651 from odinuge/kubectl-proxy-handle-error 2020-02-09 11:23:52 -08:00
logo Correct URL 2019-04-28 00:05:57 -04:00
pkg Provide OIDC discovery endpoints 2020-02-11 16:23:31 -08:00
plugin Provide OIDC discovery endpoints 2020-02-11 16:23:31 -08:00
staging Provide OIDC discovery endpoints 2020-02-11 16:23:31 -08:00
test Provide OIDC discovery endpoints 2020-02-11 16:23:31 -08:00
third_party Merge pull request #83385 from daxmc99/docstring-change 2019-11-08 13:48:11 -08:00
translations Move pkg/kubectl/cmd/util and subdirs to staging 2019-07-29 13:08:41 -07:00
vendor Bump to latest SMD to pick up performance optimizations 2020-02-07 16:11:06 -08:00
.bazelrc move build related files out of the root directory 2017-05-15 15:53:54 -07:00
.bazelversion Add .bazelversion file 2019-09-19 08:57:12 +02:00
.generated_files generated_files: remove line about /docs/.generated_docs 2019-02-11 02:54:45 +02:00
.gitattributes review staging go.mod files 2019-05-10 15:40:43 -04:00
.gitignore openapi: commit low-change code-gen+sample-apiserver specs 2019-07-12 21:04:06 +02:00
.kazelcfg.json Switch from gazel to kazel, and move kazelcfg into build/root 2017-07-18 12:48:51 -07:00
BUILD.bazel move build related files out of the root directory 2017-05-15 15:53:54 -07:00
CHANGELOG.md CHANGELOG: Move changelog, soft-link to top-level, refresh listing 2020-02-06 01:04:44 -05:00
code-of-conduct.md Update code-of-conduct.md 2017-12-20 13:33:36 -05:00
CONTRIBUTING.md Pointed to community/contributors/guide/README.md 2017-12-15 22:08:34 +05:30
go.mod Bump to latest SMD to pick up performance optimizations 2020-02-07 16:11:06 -08:00
go.sum Bump to latest SMD to pick up performance optimizations 2020-02-07 16:11:06 -08:00
LICENSE LICENSE: revert modifications to Apache license 2016-11-22 11:44:46 -08:00
Makefile move build related files out of the root directory 2017-05-15 15:53:54 -07:00
Makefile.generated_files move build related files out of the root directory 2017-05-15 15:53:54 -07:00
OWNERS Move jbeda to emeritus status. 2019-10-11 17:46:18 -04:00
OWNERS_ALIASES Add serathius to sig-instrumentation-approvers 2020-01-24 13:26:51 +01:00
README.md Make k8s.io/kubernetes dependency policy explicit 2019-10-30 10:53:02 -04:00
SECURITY_CONTACTS Update SECURITY_CONTACTS with current PSC 2019-05-29 15:22:35 +05:30
SUPPORT.md delete all duplicate empty blanks 2019-02-23 10:28:04 +08:00
WORKSPACE move build related files out of the root directory 2017-05-15 15:53:54 -07:00

Kubernetes

GoDoc Widget CII Best Practices


Kubernetes is an open source system for managing containerized applications across multiple hosts. It provides basic mechanisms for deployment, maintenance, and scaling of applications.

Kubernetes builds upon a decade and a half of experience at Google running production workloads at scale using a system called Borg, combined with best-of-breed ideas and practices from the community.

Kubernetes is hosted by the Cloud Native Computing Foundation (CNCF). If your company wants to help shape the evolution of technologies that are container-packaged, dynamically scheduled, and microservices-oriented, consider joining the CNCF. For details about who's involved and how Kubernetes plays a role, read the CNCF announcement.


To start using Kubernetes

See our documentation on kubernetes.io.

Try our interactive tutorial.

Take a free course on Scalable Microservices with Kubernetes.

To use Kubernetes code as a library in other applications, see the list of published components. Use of the k8s.io/kubernetes module or k8s.io/kubernetes/... packages as libraries is not supported.

To start developing Kubernetes

The community repository hosts all information about building Kubernetes from source, how to contribute code and documentation, who to contact about what, etc.

If you want to build Kubernetes right away there are two options:

You have a working Go environment.
mkdir -p $GOPATH/src/k8s.io
cd $GOPATH/src/k8s.io
git clone https://github.com/kubernetes/kubernetes
cd kubernetes
make
You have a working Docker environment.
git clone https://github.com/kubernetes/kubernetes
cd kubernetes
make quick-release

For the full story, head over to the developer's documentation.

Support

If you need support, start with the troubleshooting guide, and work your way through the process that we've outlined.

That said, if you have questions, reach out to us one way or another.

Analytics