Skip to main content
Schemaobject

io.k8s.api.authorization.v1.SubjectAccessReviewSpec

SubjectAccessReviewSpec is a description of the access request. Exactly one of resourceAttributes and nonResourceAttributes must be set

Source
specs/apis__authorization.k8s.io__v1_openapi.json
Revision
9a79c3bd90f7
Active snapshot
2a9112600697
extra object
optional

extra corresponds to the user.Info.GetExtra() method from the authenticator. Since that is input to the authorizer it needs a reflection here.

groups array
optional

groups is the groups you're testing for.

nonResourceAttributes
optional

nonResourceAttributes describes information for a non-resource access request

resourceAttributes
optional

resourceAttributes describes information for a resource access request

uid string
optional

uid information about the requesting user.

user string
optional

user is the user you're testing for. If you specify "User" but not "Groups", then is it interpreted as "What if User were not a member of any groups