Repository navigation
Add the auth get-token command for kubeconfigs naming the Rancher user - #698
Open
pmatseykanets wants to merge 1 commit into
Open
pmatseykanets wants to merge 1 commit into
pmatseykanets wants to merge 1 commit into
Conversation
Rancher is adding a kubeconfig form whose exec entry runs `rancher auth get-token --server <url> --cluster <id> --user-id <user id> --auth-provider <provider>`. The CLI had no `auth get-token` command, and kubectl failed on every such kubeconfig. The `--auth-provider` value Rancher writes is the provider's name, such as `local`, which the CLI matched only against provider types. Added `rancher auth get-token`. It signs in and caches the credential the same way as `rancher token`, with the user id in the cache key in place of the kubeconfig entry name, and it offers no default at the username prompt. `--cluster` is optional; without it the token is not scoped to a cluster. `--auth-provider` takes a provider's name or type, and a name wins over another provider's type. The user id is not verified. `rancher token` is unchanged.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Issue: rancher/rancher#57716
Problem
Rancher is adding a kubeconfig form whose exec entry runs
rancher auth get-token --server <url> --cluster <id> --user-id <user id> --auth-provider <provider>. The CLI had noauth get-tokencommand, and kubectl failed on every such kubeconfig. The--auth-providervalue Rancher writes is the provider's name, such aslocal, which the CLI matched only against provider types.Solution
Added
rancher auth get-token. It signs in and caches the credential the same way asrancher token, with the user id in the cache key in place of the kubeconfig entry name, and it offers no default at the username prompt.--clusteris optional; without it the token is not scoped to a cluster.--auth-providertakes a provider's name or type, and a name wins over another provider's type. The user id is not verified.rancher tokenis unchanged.