Skip to content

Use the TokenRequest API to support >=1.24 clusters #9610

Description

@crenshaw-dev

Summary

2.4 creates a non-expiring ServiceAccount token Secret on argocd cluster add for 1.24 clusters.

Instead, Argo CD should use the TokenRequest API.

Motivation

Kubernetes recommends using the TokenRequest API rather than relying on tokens that don't expire.

Metadata

Metadata

Assignees

Labels

bugSomething isn't workingcomponent:authIssues related to login, SSO, OIDC, claims, user session and authentication proxy.component:cliIssue related to the Argo CD CLIenhancementNew feature or requestsecuritySecurity related issuestriage/pendingThis issue needs further triage to be correctly classifiedtype:tech-debtEnhancement such as refactor invisible for the end user

Type

No type
No fields configured for issues without a type.

Projects

Status
Backlog

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions