【发布时间】:2017-07-26 10:21:17
【问题描述】:
kubectl config set-credentials USER_NAME \
--auth-provider=oidc \
--auth-provider-arg=idp-issuer-url=( issuer url ) \
--auth-provider-arg=client-id=( your client id ) \
--auth-provider-arg=client-secret=( your client secret ) \
--auth-provider-arg=refresh-token=( your refresh token ) \
--auth-provider-arg=idp-certificate-authority=( path to your ca certificate ) \
--auth-provider-arg=id-token=( your id_token ) \
--auth-provider-arg=extra-scopes=( comma separated list of scopes to add to "openid email profile", optional )
这足以用 kubernetes 配置 openid-connect 吗? 谁能告诉我有什么价值
1.发行人网址 2.刷新令牌 3. ca证书路径 4.额外范围 5. id-token
也只是为了确认,我想知道客户端密码和客户端 ID 是否与创建的 google 凭据相同。
【问题讨论】: