tencent cloud

Tencent Kubernetes Engine

DocumentaçãoTencent Kubernetes EngineRelease Notes and AnnouncementsRelease Notestcr-assistant-oidc (TCR Cross-Account Password-Free Pull Plugin)

tcr-assistant-oidc (TCR Cross-Account Password-Free Pull Plugin)

Download
Modo Foco
Tamanho da Fonte
Última atualização: 2026-08-14 15:15:27
Traduzido e Verificado por IA

Component Introduction

The tcr-assistant-oidc plugin (TCR cross-account password-free image pull plugin) dynamically generates and rotates temporary access credentials for TCR instances in your clusters based on the OIDC authentication mechanism. It supports password-free image pulls from both the same account and cross-accounts. New applications can pull images from TCR Enterprise Edition instances under the same or other accounts without specifying imagePullSecrets. The plugin also supports configuring custom domains.
Main Features:
Automatic Authentication: Pods within the cluster can directly pull private images from TCR Enterprise Edition without manually configuring Secrets.
Access Acceleration: It supports accessing TCR via a private network, reducing image pull latency and public network bandwidth consumption.
Cross-Account Pull: It supports pulling images from both the same account and cross-accounts.
Dynamic Keys: These are dynamic temporary keys that are automatically rotated.

Version List

Release Date
Chart Version
Change Content
Limitations and Impacts
2026-07-28
1.0.2
Supports custom domains and STS private network endpoints.
None
2026-03-06
1.0.1
Optimization of Pod anti-affinity scheduling.
None
2025-12-11
1.0.0
The initial version has been released.
Dynamic key rotation is implemented based on the OIDC + STS temporary credential mechanism.
It supports password-free image pulls from TCR Enterprise Edition instances under both the same account and cross-accounts.
It supports password-free image pulls from Account A's TCR by clusters under Account B through CAM role bearer authorization.
It supports controlling the scope of credential injection at the granularity of namespaces and serviceAccounts.
It supports configuring the expiration time of credentials.
It supports configuring Webhook namespace exclusions.
It supports both the amd64 and arm64 architectures.
Only supports TKE clusters running Kubernetes version 1.20 or later.

Comparison with tcr-assistant

For details about tcr-assistant, see TCR Plugin.
Capability
tcr-assistant
tcr-assistant-oidc
Credential type
Static long-term credentials (username + password).
Dynamic temporary keys, automatically rotated.
Cross-account pull
Only supports pulling from the same account.
Supports pulling from the same account and across accounts.
Security
Long-term key exposure risk.
Temporary keys are rotated periodically and automatically expire.



Ajuda e Suporte

Esta página foi útil?

comentários