Commit Graph

  • 3eba3e07c6 Merge pull request #669 from vmware-tanzu/dependabot/go_modules/github.com/golang/mock-1.6.0 Matt Moyer 2021-06-15 18:49:23 -07:00
  • 9f06869f76 Bump github.com/golang/mock from 1.5.0 to 1.6.0 dependabot[bot] 2021-06-16 01:22:04 +00:00
  • 3f41261580 Merge pull request #673 from mattmoyer/refactor-static-client-struct-second-attempt Matt Moyer 2021-06-15 17:37:08 -07:00
  • 551249fb69 Use a custom type for our static CLI client (smaller change). Matt Moyer 2021-06-15 11:27:30 -05:00
  • 1a610022cf Merge pull request #671 from enj/enj/i/eks_rbac Mo Khan 2021-06-15 11:46:24 -04:00
  • 524ff21b7f TestServiceAccountPermissions: handle extra permissions on EKS Monis Khan 2021-06-15 11:17:59 -04:00
  • 913c140be8 Update the latest version number in the docs. Matt Moyer 2021-06-15 09:46:51 -05:00
  • e06c696bea Merge pull request #670 from enj/enj/f/impersonator_always_authz v0.9.2 Mo Khan 2021-06-14 16:16:12 -04:00
  • 269db6b7c2 impersonator: always authorize every request Monis Khan 2021-06-11 14:03:18 -04:00
  • addf632e7c impersonator: add docs regarding limited serivce account Monis Khan 2021-06-11 13:56:11 -04:00
  • 87489da316 Merge pull request #667 from enj/enj/f/impersonator_distinct_sa Mo Khan 2021-06-11 15:36:28 -04:00
  • 898f2bf942 impersonator: run as a distinct SA with minimal permissions Monis Khan 2021-06-09 19:00:54 -04:00
  • 918c50f6a7 Merge pull request #666 from vmware-tanzu/dependabot/go_modules/gopkg.in/square/go-jose.v2-2.6.0 Matt Moyer 2021-06-10 15:06:55 -07:00
  • 9ca82116f1 Update ROADMAP.md Matt Moyer 2021-06-10 12:45:23 -05:00
  • 564c1f8ae5 Update ROADMAP.md Matt Moyer 2021-06-10 10:27:20 -05:00
  • c88aad873b Bump gopkg.in/square/go-jose.v2 from 2.5.1 to 2.6.0 dependabot[bot] 2021-06-08 05:41:45 +00:00
  • 9d27e6b4c6 Merge pull request #665 from enj/enj/i/impersonator_dead_code Mo Khan 2021-06-04 16:12:08 -04:00
  • 5b327a2b37 impersonator: remove redundant deleteKnownImpersonationHeaders logic Monis Khan 2021-06-04 15:22:01 -04:00
  • 7114988eec Merge pull request #663 from vmware-tanzu/dependabot/docker/golang-1.16.5 Matt Moyer 2021-06-04 09:20:44 -05:00
  • 3a47060256 Merge pull request #645 from enj/enj/f/anon_impersonation_proxy Mo Khan 2021-06-04 09:28:14 -04:00
  • 492f6cfddf impersonator: honor anonymous authentication being disabled Benjamin A. Petersen 2021-05-27 10:17:19 -04:00
  • f417f706b9 Bump golang from 1.16.4 to 1.16.5 dependabot[bot] 2021-06-04 06:00:24 +00:00
  • 02335e2ade Bump the latest version referenced in the docs. Matt Moyer 2021-06-03 17:25:32 -05:00
  • 9b9e733a7d Merge pull request #662 from mattmoyer/parameterize-test-images v0.9.1 Matt Moyer 2021-06-03 15:53:13 -05:00
  • df78e00df3 Parameterize our test images in ytt. Matt Moyer 2021-06-03 13:24:26 -05:00
  • b5ed4e6a13 Merge pull request #660 from mattmoyer/fix-credentialissuer-service-type-field-typo Matt Moyer 2021-06-03 14:01:14 -05:00
  • 500b444bad Merge pull request #657 from vmware-tanzu/fix-ldap-supervisor-login-test-flake Matt Moyer 2021-06-03 13:31:15 -05:00
  • d3e2859238 Merge pull request #658 from vmware-tanzu/fix-impersonation-notfound-handling Matt Moyer 2021-06-03 13:30:54 -05:00
  • 5686591420 Avoid a rare flake in TestSupervisorLogin. Matt Moyer 2021-06-02 13:36:48 -05:00
  • 6903196c18 Fix a data race in TestImpersonationProxy. Matt Moyer 2021-06-02 14:00:35 -05:00
  • af4cd1b515 Tolerate NotFound when deleting services in impersonatorconfig. Matt Moyer 2021-06-02 13:47:54 -05:00
  • 2acfafd5a5 Merge pull request #656 from vmware-tanzu/fix-credentialissuer-test-flake Matt Moyer 2021-06-03 12:03:22 -05:00
  • a5067cdbb3 Update ROADMAP.md anjalitelang 2021-06-03 12:33:36 -04:00
  • 5aa08756e0 Fix typo in CredentialIssuer ytt template. Matt Moyer 2021-06-02 14:48:18 -05:00
  • 0e66b0b165 Remove an invalid test assertion in TestCredentialIssuer. Matt Moyer 2021-06-02 12:02:34 -05:00
  • 87660611d2 Tweak blog post to add a shoutout. Matt Moyer 2021-06-02 11:28:54 -05:00
  • 9968c0d234 Fix my fix 🤦🏻 . Matt Moyer 2021-06-02 11:06:03 -05:00
  • 193fcb87bb Fix a typo on the "Community Meetings" time. Matt Moyer 2021-06-02 11:05:29 -05:00
  • a08e4ec043 Update architecture.md Ryan Richard 2021-06-02 08:54:04 -07:00
  • e38a7548cc Link the v0.9.0 release from the blog post. Matt Moyer 2021-06-02 10:24:17 -05:00
  • b5dea42bbe Update CLI docs for v0.9.0 release Pinny 2021-06-02 15:22:13 +00:00
  • d06fe15a68 Merge pull request #655 from mattmoyer/update-docs-for-v0.9.0 Matt Moyer 2021-06-02 10:07:02 -05:00
  • e6301f0e74 Update latest version number in docs. Matt Moyer 2021-06-02 10:05:07 -05:00
  • aca33e45fb Fix blog post date to match actual v0.9.0 release. Matt Moyer 2021-06-02 10:02:59 -05:00
  • 46825b1c9f Merge pull request #653 from mattmoyer/fix-impersonation-test-flake v0.9.0 Matt Moyer 2021-06-01 16:51:16 -05:00
  • 2ee3cec5ed Refactor TestImpersonationProxy "apply annotation" test for clarity. Matt Moyer 2021-06-01 15:01:42 -05:00
  • 75d92079e4 Allow some flexibility in "kubectl logs --tail=10" test. Matt Moyer 2021-06-01 14:58:32 -05:00
  • 0be77c3bf2 Merge pull request #651 from vmware-tanzu/dependabot/go_modules/github.com/creack/pty-1.1.13 Matt Moyer 2021-06-01 15:50:38 -05:00
  • d4a6a61560 Bump github.com/creack/pty from 1.1.12 to 1.1.13 dependabot[bot] 2021-06-01 20:15:47 +00:00
  • abc3df8df9 Merge pull request #637 from vmware-tanzu/ldap_docs Ryan Richard 2021-06-01 12:59:58 -07:00
  • 5932bce54d Merge branch 'main' into ldap_docs Ryan Richard 2021-06-01 12:59:38 -07:00
  • 41ff3e0917 Merge pull request #652 from mattmoyer/fix-impersonation-test-flake Matt Moyer 2021-06-01 14:41:07 -05:00
  • f62c6e806d In TestImpersonationProxy tests, avoid mutating anything in parallel block of tests. Matt Moyer 2021-06-01 13:25:31 -05:00
  • 79e3980f1f Fix nil function deference in an integration test from previous commit Ryan Richard 2021-05-28 17:06:01 -07:00
  • 8f2e8b8a6c Merge branch 'main' into ldap_docs Ryan Richard 2021-05-28 16:20:02 -07:00
  • e4fda80fcc Merge pull request #650 from mattmoyer/do-not-log-usernames-that-might-be-passwords Ryan Richard 2021-05-28 16:16:32 -07:00
  • 5263e0bae5 Merge branch 'main' into do-not-log-usernames-that-might-be-passwords Ryan Richard 2021-05-28 16:16:01 -07:00
  • b8205006ca Enable skipping of LDAP int tests when a firewall will block them Ryan Richard 2021-05-28 16:12:57 -07:00
  • 7ee1f8c441 In LDAP, do not log username until we know the user exists. Matt Moyer 2021-05-28 16:37:31 -05:00
  • 854903c4ed Merge pull request #649 from vmware-tanzu/change_ldap_groupname_default Ryan Richard 2021-05-28 14:04:37 -07:00
  • cedbe82bbb Default groupSearch.attributes.groupName to "dn" instead of "cn" Ryan Richard 2021-05-28 13:27:11 -07:00
  • a741041737 Merge pull request #648 from mattmoyer/2021-05-28-dep-upgrades Matt Moyer 2021-05-28 14:31:58 -05:00
  • 83f418e7f2 Upgrade k8s.io/klog/v2 to v2.9.0. Matt Moyer 2021-05-28 11:00:28 -05:00
  • e25de9e559 Update ID token tests for latest Fosite. Matt Moyer 2021-05-28 10:56:33 -05:00
  • 87c7e89b13 Upgrade github.com/ory/fosite to v0.40.2. Matt Moyer 2021-05-28 09:52:49 -05:00
  • 4722422aae Fix OIDC assertion bug in TestSupervisorLogin introduced by LDAP branch Ryan Richard 2021-05-28 10:37:46 -07:00
  • a39b328778 Merge pull request #626 from vmware-tanzu/credentialissuer-spec-api Matt Moyer 2021-05-27 17:48:45 -05:00
  • 343238fa9b Merge branch 'credentialissuer-spec-api-docs' of github.com:vmware-tanzu/pinniped into credentialissuer-spec-api Matt Moyer 2021-05-27 17:12:08 -05:00
  • a69fe68362 Merge branch 'main' of github.com:vmware-tanzu/pinniped into credentialissuer-spec-api Matt Moyer 2021-05-27 17:11:40 -05:00
  • 01713c7ce1 Don't reconcile Service ports in impersonatorconfig. Matt Moyer 2021-05-27 17:10:25 -05:00
  • ab750f48aa When merging CredentialIssuer updates, don't overwrite LastUpdated. Matt Moyer 2021-05-27 17:09:12 -05:00
  • d7d8630e08 Merge branch 'main' into ldap_docs Ryan Richard 2021-05-27 14:30:02 -07:00
  • cd7f5741d8 Incorporate feedback into LDAP blog post Ryan Richard 2021-05-27 14:29:40 -07:00
  • c8dc03b06a Merge pull request #647 from vmware-tanzu/ldap_binary_uids Ryan Richard 2021-05-27 14:28:21 -07:00
  • 83001d8cce Fix typo in LDAP blog post Ryan Richard 2021-05-27 14:13:07 -07:00
  • d2251d2ea7 Use base64 binary-encoded value as UID for LDAP Ryan Richard 2021-05-27 13:47:10 -07:00
  • f330b52076 Update values.yaml to include CredentialIssuer ImpersonationProxy spec. Margo Crawford 2021-05-27 13:36:18 -07:00
  • af2af567be Merge branch 'main' of github.com:vmware-tanzu/pinniped into credentialissuer-spec-api Matt Moyer 2021-05-27 15:13:36 -05:00
  • ec2956d54e Forgot to mention the CLI in the LDAP blog post Ryan Richard 2021-05-27 13:05:45 -07:00
  • 35cf1a00c8 Merge pull request #643 from vmware-tanzu/ldap_base_in_sub Ryan Richard 2021-05-27 12:23:27 -07:00
  • 0d43105759 Blog post for LDAP release Ryan Richard 2021-05-27 12:06:01 -07:00
  • 67d5c91713 Wait for successful TCR in TestImpersonationProxy. Matt Moyer 2021-05-27 13:03:07 -05:00
  • 81148866e0 URL query escape the upstream OIDC subject in the downstream subject URL Ryan Richard 2021-05-27 09:25:48 -07:00
  • 349d3dad83 Make temporary errors return Pending in impersonatorconfig. Matt Moyer 2021-05-27 11:13:10 -05:00
  • 049abfb94c Remove a "fail fast" check from TestImpersonationProxy. Matt Moyer 2021-05-27 09:22:47 -05:00
  • 033e1f0399 Add user search base to downstream subject for upstream LDAP Ryan Richard 2021-05-26 17:04:20 -07:00
  • d2d0dae4ed Wait for credentialissuer to be updated and always use proxy on clusterip test Margo Crawford 2021-05-26 15:52:31 -07:00
  • 0a47aa4843 Adjust log levels in impersonatorconfig controller. Matt Moyer 2021-05-26 16:47:02 -05:00
  • d780bf64bc Remove references to impersonationConfigMap. Matt Moyer 2021-05-26 15:24:59 -05:00
  • b57878ebc5 Remove TODO from impersonator.go. Matt Moyer 2021-05-26 15:08:29 -05:00
  • 1932b03c39 Refactor createOrUpdateService() method. Matt Moyer 2021-05-26 15:03:04 -05:00
  • be8118ec2e Re-enable parallelism on TestImpersonatorConfigControllerSync. Matt Moyer 2021-05-26 12:57:51 -05:00
  • 1a4687a40a Switch impersonatorconfig to all singleton queues. Matt Moyer 2021-05-26 12:54:40 -05:00
  • b13c494f93 Migrate off global logger in impersonatorconfig. Matt Moyer 2021-05-26 12:42:50 -05:00
  • e5a61f3b95 IPv6 address in unit tests for ClusterIPs Margo Crawford 2021-05-26 10:30:33 -07:00
  • 9621ad9d2c More doc updates Ryan Richard 2021-05-26 10:08:03 -07:00
  • f2021f1b53 Merge branch 'credentialissuer-spec-api' of github.com:vmware-tanzu/pinniped into credentialissuer-spec-api Margo Crawford 2021-05-25 17:06:26 -07:00
  • e2fad6932f multiple cluster ips Margo Crawford 2021-05-25 17:01:42 -07:00
  • 9ee11d2a49 Merge branch 'main' into ldap_docs Ryan Richard 2021-05-25 16:19:06 -07:00
  • bf39f930d4 Some light docs wordsmithing and reordering of the sidebar Ryan Richard 2021-05-25 16:15:45 -07:00