cli-experimental icon indicating copy to clipboard operation
cli-experimental copied to clipboard

Apply documentation does not specify remote url format or mechanism

Open dcmiddle opened this issue 1 year ago • 3 comments

https://kubectl.docs.kubernetes.io/references/kubectl/apply/ does not list the ability to use URLs as in https://github.com/confidential-containers/confidential-containers/blob/main/quickstart.md kubectl apply -k github.com/confidential-containers/operator/config/release?ref=v0.8.0

I would like to understand whether apply fetches that URL implicitly using a secure mechanism like https. This would satisfy an OpenSSF Best Practices criteria meant to protect users from downloading maliciously corrupted releases.

https://kubectl.docs.kubernetes.io/references/kubectl/kustomize/ mentions a git url but without example or clarification of the mechanism.

Presumably kubectl apply uses one of the mechanisms here https://git-scm.com/book/en/v2/Git-on-the-Server-The-Protocols Which includes secure and insecure mechanisms.

dcmiddle avatar Jan 03 '24 15:01 dcmiddle

The Kubernetes project currently lacks enough contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

  • After 90d of inactivity, lifecycle/stale is applied
  • After 30d of inactivity since lifecycle/stale was applied, lifecycle/rotten is applied
  • After 30d of inactivity since lifecycle/rotten was applied, the issue is closed

You can:

  • Mark this issue as fresh with /remove-lifecycle stale
  • Close this issue with /close
  • Offer to help out with Issue Triage

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

k8s-triage-robot avatar Apr 02 '24 16:04 k8s-triage-robot

The Kubernetes project currently lacks enough active contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

  • After 90d of inactivity, lifecycle/stale is applied
  • After 30d of inactivity since lifecycle/stale was applied, lifecycle/rotten is applied
  • After 30d of inactivity since lifecycle/rotten was applied, the issue is closed

You can:

  • Mark this issue as fresh with /remove-lifecycle rotten
  • Close this issue with /close
  • Offer to help out with Issue Triage

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle rotten

k8s-triage-robot avatar May 02 '24 16:05 k8s-triage-robot

/remove-lifecycle stale

Issue is still relevant for assessing Software Supply Chain Security & OpenSSF Best Practices.

dcmiddle avatar May 02 '24 17:05 dcmiddle

The Kubernetes project currently lacks enough active contributors to adequately respond to all issues and PRs.

This bot triages issues according to the following rules:

  • After 90d of inactivity, lifecycle/stale is applied
  • After 30d of inactivity since lifecycle/stale was applied, lifecycle/rotten is applied
  • After 30d of inactivity since lifecycle/rotten was applied, the issue is closed

You can:

  • Reopen this issue with /reopen
  • Mark this issue as fresh with /remove-lifecycle rotten
  • Offer to help out with Issue Triage

Please send feedback to sig-contributor-experience at kubernetes/community.

/close not-planned

k8s-triage-robot avatar Jun 01 '24 17:06 k8s-triage-robot

@k8s-triage-robot: Closing this issue, marking it as "Not Planned".

In response to this:

The Kubernetes project currently lacks enough active contributors to adequately respond to all issues and PRs.

This bot triages issues according to the following rules:

  • After 90d of inactivity, lifecycle/stale is applied
  • After 30d of inactivity since lifecycle/stale was applied, lifecycle/rotten is applied
  • After 30d of inactivity since lifecycle/rotten was applied, the issue is closed

You can:

  • Reopen this issue with /reopen
  • Mark this issue as fresh with /remove-lifecycle rotten
  • Offer to help out with Issue Triage

Please send feedback to sig-contributor-experience at kubernetes/community.

/close not-planned

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

k8s-ci-robot avatar Jun 01 '24 17:06 k8s-ci-robot