status:
from:
- system:serviceaccount:default:trusted-app
- "system:serviceaccount:default:other-*"
conditions:
- type: Ready
status: "True"
- type: SubjectsResolved
status: "True"
status:
from:
- system:serviceaccount:default:trusted-app
- "system:serviceaccount:default:other-*"
conditions:
- type: Ready
status: "True"
- type: SubjectsResolved
status: "True"
Copy to Clipboard
Copied!
Toggle word wrap
Toggle overflow
status:
policies:
- name: my-event-policy
apiVersion: v1alpha1
conditions:
- type: Ready
status: "True"
- type: EventPoliciesReady
status: "True"
status:
policies:
- name: my-event-policy
apiVersion: v1alpha1
conditions:
- type: Ready
status: "True"
- type: EventPoliciesReady
status: "True"
Copy to Clipboard
Copied!
Toggle word wrap
Toggle overflow
如果传入的请求无法满足任何适用的 EventPolicy,它将被拒绝,并带有 HTTP 403 Forbidden 状态代码。如果多个 EventPolicies 应用到某个资源,只要它至少匹配其中一个事件,就可以接受一个事件。这样可确保未授权的事件在系统级别被阻止。
当多个 EventPolicies 应用到同一资源时,系统会并行评估它们。如果事件至少匹配一个适用的 EventPolicy,则可以接受它。这种方法允许灵活性,因为有效的事件甚至严格授权下也不会被拒绝,只要它们满足至少一个策略的要求。