top | item 28959173

(no title)

xnxn | 4 years ago

> You'd need get permissions for that.

I'm afraid not. HTTP GET on a collection endpoint (which is the operation represented by the list verb) returns the full object content.

https://kubernetes.io/docs/reference/access-authn-authz/auth...

discuss

order

cassianoleal|4 years ago

Interesting, thanks for the reference. This is at best surprising, at worst sloppy security design IMO.