問題文
A team wants pods in a Kubernetes cluster to call OCI APIs with permissions granted to the Kubernetes service account rather than to the worker node. Which cluster configuration makes that possible?
選択肢
- An enhanced cluster, because workload identity is one of the capabilities that only enhanced clusters support.
- Any cluster, because the mapping between Kubernetes service accounts and OCI policies is part of the open source Kubernetes distribution and therefore does not depend on which kind of cluster the workload happens to run on.
- A basic cluster with an instance principal on each worker node, and every pod that lands on that node cannot be held to a narrower set of permissions.
- A basic cluster with a dynamic group that matches the cluster, and the group grants its permissions to every workload, not just to the worker node.