Skip to content

Document well-known audit annotations #29479

Closed
@tallclair

Description

@tallclair

Similar to https://kubernetes.io/docs/reference/labels-annotations-taints/ (should probably be a separate page though).

The current (2023-02-08) list of well-known audit annotations is:

  • authorization.k8s.io/decision
  • authorization.k8s.io/reason
  • podsecuritypolicy.policy.k8s.io/admit-policy
  • podsecuritypolicy.policy.k8s.io/validate-policy
  • [PodSecurity] Extra audit annotations kubernetes#103923
  • authentication.k8s.io/stale-token
  • authentication.k8s.io/legacy-token
  • apiserver.latency.k8s.io/transform-response-object
  • apiserver.latency.k8s.io/etcd
  • apiserver.latency.k8s.io/serialize-response-object
  • apiserver.latency.k8s.io/response-write
  • apiserver.latency.k8s.io/mutating-webhook
  • apiserver.latency.k8s.io/validating-webhook
  • apiserver.latency.k8s.io/total
  • k8s.io/deprecated
  • k8s.io/removed-release

Metadata

Metadata

Assignees

No one assigned

    Labels

    help wantedDenotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.kind/featureCategorizes issue or PR as related to a new feature.lifecycle/frozenIndicates that an issue or PR should not be auto-closed due to staleness.priority/backlogHigher priority than priority/awaiting-more-evidence.sig/authCategorizes an issue or PR as relevant to SIG Auth.triage/acceptedIndicates an issue or PR is ready to be actively worked on.

    Type

    No type

    Projects

    Status

    Closed / Done

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions