DI
Size: a a a
DI
MF
kubectl exec -it <pod-with-curl> curl https://<apiserver>:443/
# тут должна быть ошибка про х509
kubectl exec -it <pod-with-curl> curl --cacert /var/run/secrets/kubernetes.io/serviceaccount/ca.crt https://<apiserver>:443/
# теперь должно стать "unauthorized"
MF
DI
DI
Unauthorized
🎉MF
DI
volumes:
- name: ssl-certs-kubernetes
hostPath:
path: /etc/kubernetes/ssl
- name: kubeconfig
hostPath:
path: /etc/kubernetes/kubeconfig.yaml
MF
MF
DI
DI
MF
MF
MF
MF
MF
MF