Authentication and Authorization
Rancher APIs
Kubernetes concepts
Authentication
Plugin model
Rancher: no special plugin, yes auth proxy
Impersonation
Authorization
Roles
RoleBindings
ClusterRoles
ClusterRoleBindings
Subject
Rules
Rancher Resource Heirarchy
Global - Management API
Cluster
Rancher Auth API Constructs
Authentication
Authorization
RoleTemplates
ClusterRoleTemplateBinding
ProjectRoleTemplateBinding
Groups
GroupMembers
$ kubectl get crd
NAME AGE
catalogs.management.cattle.io 2m
clusterevents.management.cattle.io 2m
clusterregistrationtokens.management.cattle.io 2m
clusterroletemplatebindings.management.cattle.io 2m
clusters.management.cattle.io 2m
dynamicschemas.management.cattle.io 2m
globalrolebindings.management.cattle.io 2m
globalroles.management.cattle.io 2m
groupmembers.management.cattle.io 2m
groups.management.cattle.io 2m
machinedrivers.management.cattle.io 2m
machines.management.cattle.io 2m
machinetemplates.management.cattle.io 2m
nodes.management.cattle.io 2m
podsecuritypolicytemplates.management.cattle.io 2m
principals.management.cattle.io 2m
projectroletemplatebindings.management.cattle.io 2m
projects.management.cattle.io 2m
roletemplates.management.cattle.io 2m
stacks.management.cattle.io 2m
templates.management.cattle.io 2m
templateversions.management.cattle.io 2m
tokens.management.cattle.io 2m
users.management.cattle.io 2m
workloads.project.cattle.io 19s