ContainerImage.Pinniped/test
Monis Khan 898f2bf942
impersonator: run as a distinct SA with minimal permissions
This change updates the impersonation proxy code to run as a
distinct service account that only has permission to impersonate
identities.  Thus any future vulnerability that causes the
impersonation headers to be dropped will fail closed instead of
escalating to the concierge's default service account which has
significantly more permissions.

Signed-off-by: Monis Khan <mok@vmware.com>
2021-06-11 12:13:53 -04:00
..
cluster_capabilities Enable skipping of LDAP int tests when a firewall will block them 2021-05-28 16:13:20 -07:00
deploy/tools Parameterize our test images in ytt. 2021-06-03 15:25:09 -05:00
integration impersonator: run as a distinct SA with minimal permissions 2021-06-11 12:13:53 -04:00
library Enable skipping of LDAP int tests when a firewall will block them 2021-05-28 16:13:20 -07:00