Documentation
¶
Overview ¶
Command access-vw-init installs the kcp-side objects the access virtual workspace needs — the APIResourceSchema, the APIExport, and the APIExportEndpointSlice the RBAC provider follows — and verifies they came up.
The APIExport and the ServiceAccount the server runs as land in <prefix>:<controllers-workspace>, default root:access:controllers. Both halves are configurable so a deployment can bring its own tree:
access-vw-init --kubeconfig=admin.kubeconfig \ --workspace-prefix=root:magic --controllers-workspace=controllers
Any missing workspace along that path is created, so the credential needs rights to create workspaces from the root down. Idempotent: safe to run on every pod start and every upgrade.
Click to show internal directories.
Click to hide internal directories.