Edits to match AKS experience thus far

This commit is contained in:
Bridget Kromhout
2019-07-14 14:17:28 -07:00
parent 3816dc43e6
commit b48e1d6f64

View File

@@ -286,12 +286,9 @@ class: extra-details
API=$(kubectl config view -o \
jsonpath="{.clusters[?(@.name==\"$AKS_NAME\")].cluster.server}")
```
- Connect without the token:
- Connect without the token, then with the token::
```bash
curl -k $API
```
- Connect with the token:
```bash
curl -k -H "Authorization: Bearer $TOKEN" $API
```
@@ -303,18 +300,12 @@ class: extra-details
## Results
- In both cases, we will get a "Forbidden" error
- Without authentication, the user is `system:anonymous`
- With authentication, it is shown as `system:serviceaccount:default:default`
- The API "sees" us as a different user
- But neither user has any rights, so we can't do nothin'
- Let's change that!
---
## Authorization in Kubernetes