⎈ k8s knowledge compiler

Subject [page]deterministic

Subject contains a reference to the object or user identities a role binding applies to. This can either hold a direct API object reference, or a value for non-objects such as user and group names.

referencesecurity

`apiVersion: rbac.authorization.k8s.io/v1`

`import "k8s.io/api/rbac/v1"`

## Subject {#Subject}

Subject contains a reference to the object or user identities a role binding applies to. This can either hold a direct API object reference, or a value for non-objects such as user and group names.

<hr>

<table> <thead><tr><th>Field</th><th>Description</th></tr></thead> <tbody> <tr> <td><code>apiGroup</code><br/><em>string</em></td> <td>APIGroup holds the API group of the referenced subject. Defaults to "" for ServiceAccount subjects. Defaults to "rbac.authorization.k8s.io" for User and Group subjects.</td> </tr> <tr> <td><code>kind</code>&nbsp;<strong>*</strong><br/><em>string</em></td> <td>Kind of object being referenced. Values defined by this API group are "User", "Group", and "ServiceAccount". If the Authorizer does not recognized the kind value, the Authorizer should report an error.</td> </tr> <tr> <td><code>name</code>&nbsp;<strong>*</strong><br/><em>string</em></td> <td>Name of the object being referenced.</td> </tr> <tr> <td><code>namespace</code><br/><em>string</em></td> <td>Namespace of the referenced object. If the object kind is non-namespace, such as "User" or "Group", and this value is not empty the Authorizer should report an error.</td> </tr> </tbody> </table>

Sources

reference/kubernetes-api/definitions/subject-v1-rbac.md · docSubject

Related (2)

part_of Subject {#Subject}describes conf=1
api_for Subjectdocuments API object conf=1

← all Docs