Kubernetes controller for multi-tenancy. It propagates resources between namespaces accurately and allows tenant users to create/delete sub-namespaces.
The current implementation can propagate ServiceAccounts, but the propagated ServiceAccounts
won't work because the Secret tokens issued for them in the parent namespace are not propagated.
The issued Secrets do not have metadata.ownerRerefences, so accurate.cybozu.com/propagate-generated cannot be used either.
What
The current implementation can propagate ServiceAccounts, but the propagated ServiceAccounts won't work because the Secret tokens issued for them in the parent namespace are not propagated.
The issued Secrets do not have
metadata.ownerRerefences
, soaccurate.cybozu.com/propagate-generated
cannot be used either.How
Propagate ServiceAccounts without
secrets
field.Checklist