build1 distinct publisher
Kubelet takes over delivering an X.509 identity to each pod
KEP-4317 pairs a pod-scoped certificate request with a projected volume, so the kubelet provisions the key and kube-apiserver enforces node restriction. What is left for a signer to do is the CA work.
Publishers:kubernetes.dev
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives40
- Confidence