Hi Max and all,I am not yet as far as you, but I would like to authz all daemons in the 23.0 cluster with tokens limited to their specific roles.
I guess, that your finding would mean, that the collector would have to have a condor token also including the startd capability, right? But I guess the collector has necessarily all privileges as the token signer by nature of its role, or? (or asking the other way round, can a collector be constraint on the token level in addition to the config to specific capabilities?)
Cheers, Thomas
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature