Configure Service Accounts for Pods | Kubernetes
Kubernetes offers two distinct ways for clients that run within your cluster, or that otherwise have a relationship to your cluster's control plane to authenticate to the API server. A service account provides an identity for processes that run in a Pod, and maps to a ServiceAccount object. When you authenticate to…
Configure a Security Context for a Pod or Container | Kubernetes
A security context defines privilege and access control settings for a Pod or Container. Security context settings include, but are not limited to: Discretionary Access Control: Permission to access an object, like a file, is based on user ID (UID) and group ID (GID). Security Enhanced Linux (SELinux): Objects are…
Resize CPU and Memory Resources assigned to Pods | Kubernetes
Feature state: Beta since Kubernetes v1.36; enabled by default This page explains how to change the CPU and memory resources set at the Pod level without recreating the Pod. The In-place Pod Resize feature allows modifying resource allocations for a running Pod, avoiding application disruption. The process for…
Verify Signed Kubernetes Artifacts | Kubernetes
Feature state: Beta since Kubernetes v1.26 Before you beginYou will need to have the following tools installed: cosign (install guide) curl (often provided by your operating system) jq (download jq) Verifying binary signaturesThe Kubernetes release process signs all binary artifacts (tarballs, SPDX files, standalone…
Using CoreDNS for Service Discovery | Kubernetes
This page describes the CoreDNS upgrade process and how to install CoreDNS. Before you beginYou need to have a Kubernetes cluster, and the kubectl command-line tool must be configured to communicate with your cluster. It is recommended to run this tutorial on a cluster with at least two nodes that are not acting as…
