kubernetes v1.37
SubjectAccessReviewSpec
SubjectAccessReviewSpec is a description of the access request. Exactly one of resourceAttributes and nonResourceAttributes must be set
| Field / Type | Description |
|---|---|
extra corresponds to the user.Info.GetExtra() method from the authenticator. Since that is input to the authorizer it needs a reflection here. | |
groups is the groups you're testing for.
| |
nonResourceAttributes describes information for a non-resource access request | |
resourceAttributes describes information for a resource access request | |
uid | uid information about the requesting user. |
user | user is the user you're testing for. If you specify "User" but not "Groups", then is it interpreted as "What if User were not a member of any groups |