Kubernetes

Mint a cluster token

Exchanges the caller's API key or session for a short-lived bearer token that only this cluster accepts, returned as an ExecCredential so a kubectl exec credential plugin can print it as is. The token carries cluster-admin and expires after one hour; mint another rather than storing it. orl kube token is such a plugin, and orl kube kubeconfig writes a kubeconfig that runs it. A cluster that is deleting or failed answers 409 INVALID_CLUSTER_STATE. A restricted or pending organization can still mint. Needs clusters:write on an API key, or the owner, admin or member role on a session.

post/v1/kubernetes/clusters/{id}/token

Path parameters

idstring required

Response

A cluster token

apiVersion'client.authentication.k8s.io/v1' required
kind'ExecCredential' required

Changes

Changed in 1 of the 40 revisions of this API.1