PodSecurityPolicyReview checks which service accounts (not users, since that would be cluster-wide) can create the PodTemplateSpec
in question.
object
PodSecurityPolicySelfSubjectReview checks whether this user/SA tuple can create the PodTemplateSpec
object
PodSecurityPolicySubjectReview checks whether a particular user/SA tuple can create the PodTemplateSpec.
object
RangeAllocation is used so we can easily expose a RangeAllocation typed for security group
object
SecurityContextConstraints governs the ability to make requests that affect the SecurityContext that will be applied to a container. For historical reasons SCC was exposed under the core Kubernetes API group. That exposure is deprecated and will be removed in a future release - users should instead use the security.openshift.io group to manage SecurityContextConstraints.
object