Conversation
…gistries Signed-off-by: Will Refvem 文仁 <wbrefvem@gmail.com>
PR Summary by QodoDocument service account requirements for private registry access
AI Description
Diagram
High-Level Assessment
Files changed (1)
|
|
🚀 Preview is available at: https://pr-648--konflux-docs.netlify.app |
Code Review by Qodo
1.
|
Signed-off-by: Will Refvem 文仁 <wbrefvem@gmail.com>
|
🚀 Preview is available at: https://pr-648--konflux-docs.netlify.app |
Signed-off-by: Will Refvem 文仁 <wbrefvem@gmail.com>
|
🚀 Preview is available at: https://pr-648--konflux-docs.netlify.app |
Signed-off-by: Will Refvem 文仁 <wbrefvem@gmail.com>
|
🚀 Preview is available at: https://pr-648--konflux-docs.netlify.app |
|
🚀 Preview is available at: https://pr-648--konflux-docs.netlify.app |
|
🚀 Preview is available at: https://pr-648--konflux-docs.netlify.app |
Signed-off-by: Will Refvem 文仁 <wbrefvem@gmail.com>
|
🚀 Preview is available at: https://pr-648--konflux-docs.netlify.app |
|
🚀 Preview is available at: https://pr-648--konflux-docs.netlify.app |
|
🚀 Preview is available at: https://pr-648--konflux-docs.netlify.app |
|
/lgtm |
|
🚀 Preview is available at: https://pr-648--konflux-docs.netlify.app |
Summary
Documents that tokens are only issued to service accounts matching the naming pattern konflux-bot-[0-2] (e.g. konflux-bot-0, konflux-bot-1).
Changes
Motivation
The previous guidance was out of date: it stated that service account tokens do not expire and omitted the naming-pattern requirement, the ClusterRole assignments, and the token-duration constraints that users now need to follow.
EDIT: Number of allowed SAs per namespace has been reduced to 3