Directories
¶
| Path | Synopsis |
|---|---|
|
cmd
|
|
|
access-vw
command
|
|
|
init
command
Command access-vw-init installs the kcp-side objects the access virtual workspace needs — the APIResourceSchema, the APIExport, and the APIExportEndpointSlice the RBAC provider follows — and verifies they came up.
|
Command access-vw-init installs the kcp-side objects the access virtual workspace needs — the APIResourceSchema, the APIExport, and the APIExportEndpointSlice the RBAC provider follows — and verifies they came up. |
|
scar-to-kubeconfig
command
Command scar-to-kubeconfig calls the SCAR endpoint with a bearer token and writes a kubeconfig with one context per authorized cluster.
|
Command scar-to-kubeconfig calls the SCAR endpoint with a bearer token and writes a kubeconfig with one context per authorized cluster. |
|
config
|
|
|
apiexport
Package apiexport holds the kcp-side assets the access virtual workspace needs in the workspace that hosts its APIExport: the APIResourceSchema for SelfClusterAccessReview, the APIExport itself, the RBAC that makes the export bindable, and the APIExportEndpointSlice the RBAC provider follows.
|
Package apiexport holds the kcp-side assets the access virtual workspace needs in the workspace that hosts its APIExport: the APIResourceSchema for SelfClusterAccessReview, the APIExport itself, the RBAC that makes the export bindable, and the APIExportEndpointSlice the RBAC provider follows. |
|
controller
Package controller holds the identity the access virtual workspace runs as: a ServiceAccount in the workspace that hosts the APIExport, its token, and the RBAC it needs.
|
Package controller holds the identity the access virtual workspace runs as: a ServiceAccount in the workspace that hosts the APIExport, its token, and the RBAC it needs. |
|
pkg
|
|
|
accessprovider
Package accessprovider defines the AccessProvider interface — the writer-side seam between the access graph and the various sources of authorization data that may populate it.
|
Package accessprovider defines the AccessProvider interface — the writer-side seam between the access graph and the various sources of authorization data that may populate it. |
|
bootstrap
Package bootstrap installs the kcp-side objects the access virtual workspace needs and verifies they came up.
|
Package bootstrap installs the kcp-side objects the access virtual workspace needs and verifies they came up. |
|
graph
Package graph provides an in-memory RBAC permission map for kcp.
|
Package graph provides an in-memory RBAC permission map for kcp. |
|
rbacprovider
Package rbacprovider implements the kcp-native RBAC AccessProvider.
|
Package rbacprovider implements the kcp-native RBAC AccessProvider. |
|
server
Package server wires the Access Virtual Workspace binary together: the shared access graph, the RBAC provider that populates it, and a virtual-workspace root apiserver (kcp virtual-workspace-framework) serving the access virtual workspace at /services/access behind kcp's front-proxy.
|
Package server wires the Access Virtual Workspace binary together: the shared access graph, the RBAC provider that populates it, and a virtual-workspace root apiserver (kcp virtual-workspace-framework) serving the access virtual workspace at /services/access behind kcp's front-proxy. |
|
virtual
Package virtual provides shared building blocks for the virtual workspaces served by this binary, built on the kcp virtual-workspace-framework.
|
Package virtual provides shared building blocks for the virtual workspaces served by this binary, built on the kcp virtual-workspace-framework. |
|
virtual/scar
Package scar implements the SelfClusterAccessReview API of the Access Virtual Workspace.
|
Package scar implements the SelfClusterAccessReview API of the Access Virtual Workspace. |
|
sdk
|
|
|
apis/access/v1alpha1
Package v1alpha1 holds the API types for the Access Virtual Workspace (group access.contrib.kcp.io).
|
Package v1alpha1 holds the API types for the Access Virtual Workspace (group access.contrib.kcp.io). |
Click to show internal directories.
Click to hide internal directories.