mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 15:27:27 +00:00
feat: updated doc for k8s policy
This commit is contained in:
+12
@@ -61,6 +61,18 @@ For methods like OIDC, these come as claims in the token and can be made availab
|
|||||||
```
|
```
|
||||||
|
|
||||||
<img src="/images/platform/access-controls/abac-policy-oidc-format.png" />
|
<img src="/images/platform/access-controls/abac-policy-oidc-format.png" />
|
||||||
|
|
||||||
|
</Tab>
|
||||||
|
<Tab title="Kubernetes Login Attributes">
|
||||||
|
For identities authenticated using Kubernetes, the service account's namespace and name are available in their policy and can be accessed as follows:
|
||||||
|
|
||||||
|
```
|
||||||
|
{{ identity.auth.kubernetes.namespace }}
|
||||||
|
{{ identity.auth.kubernetes.name}}
|
||||||
|
```
|
||||||
|
|
||||||
|
<img src="/images/platform/access-controls/abac-policy-k8s-format.png" />
|
||||||
|
|
||||||
</Tab>
|
</Tab>
|
||||||
<Tab title="Other Authentication Method Attributes">
|
<Tab title="Other Authentication Method Attributes">
|
||||||
At the moment we only support OIDC claims. Payloads on other authentication methods are not yet accessible.
|
At the moment we only support OIDC claims. Payloads on other authentication methods are not yet accessible.
|
||||||
|
|||||||
Binary file not shown.
|
After Width: | Height: | Size: 538 KiB |
Reference in New Issue
Block a user