Skip to content

Consider adding Tokenrequest #84

Open
@tychota

Description

@tychota

Problem it solves

Probably "Wishlist priority"

When Installing latest istio (1.6.0) at the time of writing, I did see the warning:

Detected that your cluster does not support third party JWT authentication. Falling back to less secure first party JWT. See https://istio.io/docs/ops/best-practices/security/#configure-third-party-service-account-tokens for details.

What it is

See https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/#service-account-token-volume-projection

What to modify on kubelet

See https://jpweber.io/blog/a-look-at-tokenrequest-api/

I think that some certificate must be created and shared, then a few options must be added to kubelet command.

Next steps

Is it interesting for hobby-kube ?

If yes, I may find some times trying this on my own cluster soon and if so I will open a PR to both Guide and provisioning.
If not, feel free to close this issue.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions