Skip to content

Commit

Permalink
Merge pull request kubernetes#12469 from xiejunan/auth_example
Browse files Browse the repository at this point in the history
change "ns" to "namespace" in example and doc for ABAC authorization
  • Loading branch information
Marek Grabowski committed Aug 10, 2015
2 parents d3b8dbe + 8d99ba9 commit 08f67e5
Show file tree
Hide file tree
Showing 2 changed files with 3 additions and 3 deletions.
2 changes: 1 addition & 1 deletion docs/admin/authorization.md
Original file line number Diff line number Diff line change
Expand Up @@ -111,7 +111,7 @@ To permit an action Policy with an unset namespace applies regardless of namespa
1. Alice can do anything: `{"user":"alice"}`
2. Kubelet can read any pods: `{"user":"kubelet", "resource": "pods", "readonly": true}`
3. Kubelet can read and write events: `{"user":"kubelet", "resource": "events"}`
4. Bob can just read pods in namespace "projectCaribou": `{"user":"bob", "resource": "pods", "readonly": true, "ns": "projectCaribou"}`
4. Bob can just read pods in namespace "projectCaribou": `{"user":"bob", "resource": "pods", "readonly": true, "namespace": "projectCaribou"}`

[Complete file example](http://releases.k8s.io/HEAD/pkg/auth/authorizer/abac/example_policy_file.jsonl)

Expand Down
4 changes: 2 additions & 2 deletions pkg/auth/authorizer/abac/example_policy_file.jsonl
Original file line number Diff line number Diff line change
Expand Up @@ -5,5 +5,5 @@
{"user":"kubelet", "readonly": true, "resource": "services"}
{"user":"kubelet", "readonly": true, "resource": "endpoints"}
{"user":"kubelet", "resource": "events"}
{"user":"alice", "ns": "projectCaribou"}
{"user":"bob", "readonly": true, "ns": "projectCaribou"}
{"user":"alice", "namespace": "projectCaribou"}
{"user":"bob", "readonly": true, "namespace": "projectCaribou"}

0 comments on commit 08f67e5

Please sign in to comment.