-
Notifications
You must be signed in to change notification settings - Fork 463
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
kube-apiserver/audit-policy: document oauth token logging in 4.6+ #684
kube-apiserver/audit-policy: document oauth token logging in 4.6+ #684
Conversation
78d8b1a
to
303b14e
Compare
and by removing the exception for these resources in the `WriteRequestBodies` and `AllRequestBodies` policies. | ||
New cluster deployed with 4.6 or later are identified through the `oauth-apiserver.openshift.io/secure-token-storage: true` annotation | ||
on the `apiservers.config.openshift.io/v1` resource. Old cluster upgraded from 4.5 or older, don't have this annotation and hence do not | ||
audit log `authaccesstokens` and `oauthauthorizetokens`, not even on metadata level as it is not know whether old, non-sha256 hashed tokens |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
not even on metadata level as it is not know whether old
should read not known
@@ -287,6 +311,11 @@ The profile translate like this: | |||
# catch-all rule to log all other requests with request and response payloads | |||
- level: RequestResponse | |||
``` | |||
|
|||
With secure OAuth storage in-place (compare "Logging of Token with Secure OAuth Storage" section) and |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
compare "Logging of Token with Secure OAuth Storage" section
should be
compared to
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
it should be a reference. I write "see" instead.
303b14e
to
b70991a
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/lgtm
/approve |
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: EmilyM1, mfojtik The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Documenting openshift/library-go#894 and openshift/cluster-authentication-operator#324.