← 문제 라이브러리
K8s Intermediate K8S 351 · 16 min

A ServiceAccount token audience is correct for the main API call while an admission sidecar now forwards the same token to a different verifier during a staged decommission

The pod identity works in one place and fails when reused in a path with a stricter audience check. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.

Pro
시나리오

The pod identity works in one place and fails when reused in a path with a stricter audience check. The service …

구독하면 이어서 볼 수 있어요

이 문제의 전체 시나리오와 점검 체크리스트, 복구 순서, 모범 풀이는 Pro 구독에서 열립니다.

구독 안내 보기