Throw error for k8s rotation

This commit is contained in:
Fang-Pen Lin
2025-12-05 12:16:34 -08:00
parent 2afd765d9e
commit 76c324557f
@@ -130,6 +130,7 @@ export const kubernetesResourceFactory: TPamResourceFactory<
// TODO: is this the best API endpoint to use for validation? // TODO: is this the best API endpoint to use for validation?
// the SA may not have access to list ns // the SA may not have access to list ns
// maybe we should use a more specific API endpoint? // maybe we should use a more specific API endpoint?
// use /apis/authentication.k8s.io/v1/selfsubjectreviews instead?
await axios.get(`${baseUrl}/api/v1/namespaces`, { await axios.get(`${baseUrl}/api/v1/namespaces`, {
headers: { headers: {
"Content-Type": "application/json", "Content-Type": "application/json",
@@ -173,12 +174,12 @@ export const kubernetesResourceFactory: TPamResourceFactory<
} }
}; };
const rotateAccountCredentials: TPamResourceFactoryRotateAccountCredentials<TKubernetesAccountCredentials> = async ( const rotateAccountCredentials: TPamResourceFactoryRotateAccountCredentials<
rotationAccountCredentials TKubernetesAccountCredentials
) => { > = async () => {
// For Kubernetes, rotation would typically involve creating a new service account token throw new BadRequestError({
// This is a placeholder - actual rotation logic would need to be implemented based on requirements message: `Unable to rotate account credentials for ${resourceType}: not implemented`
return rotationAccountCredentials; });
}; };
const handleOverwritePreventionForCensoredValues = async ( const handleOverwritePreventionForCensoredValues = async (