Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[PodSecurity] Document webhook installation & use #30133

Closed
1 of 6 tasks
Tracked by #103559
tallclair opened this issue Oct 18, 2021 · 13 comments
Closed
1 of 6 tasks
Tracked by #103559

[PodSecurity] Document webhook installation & use #30133

tallclair opened this issue Oct 18, 2021 · 13 comments
Labels
kind/bug Categorizes issue or PR as related to a bug. lifecycle/frozen Indicates that an issue or PR should not be auto-closed due to staleness. sig/auth Categorizes an issue or PR as relevant to SIG Auth. triage/accepted Indicates an issue or PR is ready to be actively worked on.
Milestone

Comments

@tallclair
Copy link
Member

tallclair commented Oct 18, 2021

/cc @sejr @liggitt
/sig auth
/milestone v1.23

@tallclair tallclair added the kind/bug Categorizes issue or PR as related to a bug. label Oct 18, 2021
@k8s-ci-robot
Copy link
Contributor

@tallclair: You must be a member of the kubernetes/website-milestone-maintainers GitHub team to set the milestone. If you believe you should be able to issue the /milestone command, please contact your Website milestone maintainers and have them propose you as an additional delegate for this responsibility.

In response to this:

  • Webhook installation guide
  • How to manage webhook certificates
  • Kustomization
  • When to use the webhook
  • Limitations of the webhook
  • Extending the webhook (full guide to API & extension points should probably be part of the README documentation on the PodSecurity repo)

/cc @sejr @liggitt
/sig auth
/milestone v1.23

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@k8s-ci-robot k8s-ci-robot added sig/auth Categorizes an issue or PR as relevant to SIG Auth. needs-triage Indicates an issue or PR lacks a `triage/foo` label and requires one. labels Oct 18, 2021
@sftim
Copy link
Contributor

sftim commented Oct 19, 2021

/triage accepted
/lifecycle frozen

@k8s-ci-robot k8s-ci-robot added lifecycle/frozen Indicates that an issue or PR should not be auto-closed due to staleness. triage/accepted Indicates an issue or PR is ready to be actively worked on. and removed needs-triage Indicates an issue or PR lacks a `triage/foo` label and requires one. labels Oct 19, 2021
@souvikrajsingh
Copy link

@tallclair hey I would love to work on this issue, can you please assign it to me ? thank you!

@AvineshTripathi
Copy link
Contributor

@souvikrajsingh you can assign by yourself too by just commenting /assign

@souvikrajsingh
Copy link

@souvikrajsingh you can assign by yourself too by just commenting /assign

Since you mentioned , can you please tell me about this issue a bit , do I need to make documentation or I need to add these in some particular file? I'm actually new to this

@AvineshTripathi
Copy link
Contributor

According to me I think we need to have documentation for webhook in the https://github.com/kubernetes/website/tree/main/content/en/docs/concepts/security (unsure about the location of that file) @sftim @tallclair please correct me if I am wrong :)

@sejr
Copy link
Contributor

sejr commented Oct 20, 2021

@souvikrajsingh @AvineshTripathi hey there! We have an initial Task page for installing the webhook located here: #30122

It's possible that other pages, such as Concepts, will be required, but I'll defer to both Tims to clarify what they expect.

This issue is essentially tracking the topics that need to be added. I'd be happy to help you get involved; it's possible we could divide and conquer on these. Sections like extending the webhook's functionality definitely need expanding on.

@souvikrajsingh
Copy link

@sejr hey Sam would love to get involved in this, like you said please confirm and let us know. Another Question: is there any slack channel/mailing list/ discord server we can discuss further regarding this issue?

I really appreciate your help! Thanks again

@sejr
Copy link
Contributor

sejr commented Oct 20, 2021

@souvikrajsingh yes! Check out slack.kubernetes.io -- you can join the SIG Auth channel and/or send me a direct message (I'm Sam on there)

@souvikrajsingh
Copy link

souvikrajsingh commented Oct 20, 2021

@souvikrajsingh yes! Check out slack.kubernetes.io -- you can join the SIG Auth channel and/or send me a direct message (I'm Sam on there)

Thanks again, Sam! Will connect with you on Slack!!

@liggitt
Copy link
Member

liggitt commented Nov 3, 2021

#28867 open to add basic steps for webhook installation. It does not cover extending the webhook, which seems like a significantly different / more advanced topic

@reylejano
Copy link
Member

/milestone 1.23

@tallclair
Copy link
Member Author

This was resolved by #30351

Punting the extension documentation to kubernetes/kubernetes#106561

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/bug Categorizes issue or PR as related to a bug. lifecycle/frozen Indicates that an issue or PR should not be auto-closed due to staleness. sig/auth Categorizes an issue or PR as relevant to SIG Auth. triage/accepted Indicates an issue or PR is ready to be actively worked on.
Projects
Archived in project
Development

Successfully merging a pull request may close this issue.

8 participants