Jordan Liggitt
unread,Nov 7, 2025, 11:06:18 AM (3 days ago) Nov 7Sign in to reply to author
Sign in to forward
You do not have permission to delete messages in this group
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to sig-auth, i...@monis.app, Peter Engelbert, releas...@kubernetes.io, kubernetes-...@googlegroups.com, sig...@kubernetes.io, kubernete...@googlegroups.com, kubernetes-sig...@googlegroups.com
I think the exception request is reasonable:
- impactful functionality to make available
- off-by-default / opt-in, ~no risk to users who don't opt into the new feature, no change in default behavior
- a bounded timeline for the exception (EOD Tuesday, 11/11)
- several rounds of detailed reviews from sig-cli, sig-auth, and API reviewers have already been completed; I suspect we're down to one more round of updates required
That said, I am not confident I'll have review time to give the updates it between now and Tuesday.
I'm +1 on approving the exception and trying to get it in, but if it isn't merged by EOD Tuesday, it will just miss (we wouldn't extend the exception because of reviewer availability).
+1 from me, this is off by default behavior that fixes a long standing security issue with client-go credential plugins.
On Wednesday, November 5, 2025 at 9:01:00 AM UTC-5 Peter Engelbert wrote:
I am resending this since one of the email addresses had a typo, thereby splitting the thread.
-
Enhancement name:
-
Enhancement status (alpha/beta/stable):
-
SIG:
-
k/enhancements repo issue #:
-
PR #’s:
-
Additional time needed (in calendar days, due end of day AoE):
-
Reason this enhancement is critical for this milestone:
-
Risks from adding code late:
-
Risks from cutting enhancement:
Additional time will be used by reviewers from sig-auth and sig-api-machinery who need to weigh in, as well as myself in addressing feedback from the additional reviews.