NodeRestriction admission prevents kubelet taint removal (#8911)

This commit is contained in:
Jordan Liggitt
2018-06-11 20:35:26 -04:00
committed by Misty Linville
parent 4cc5461662
commit 1c4406ab30
@@ -400,6 +400,7 @@ namespace. In order to enforce integrity of that process, we strongly recommend
This admission controller limits the `Node` and `Pod` objects a kubelet can modify. In order to be limited by this admission controller, This admission controller limits the `Node` and `Pod` objects a kubelet can modify. In order to be limited by this admission controller,
kubelets must use credentials in the `system:nodes` group, with a username in the form `system:node:<nodeName>`. kubelets must use credentials in the `system:nodes` group, with a username in the form `system:node:<nodeName>`.
Such kubelets will only be allowed to modify their own `Node` API object, and only modify `Pod` API objects that are bound to their node. Such kubelets will only be allowed to modify their own `Node` API object, and only modify `Pod` API objects that are bound to their node.
In Kubernetes 1.11+, kubelets are not allowed to update or remove taints from their `Node` API object.
Future versions may add additional restrictions to ensure kubelets have the minimal set of permissions required to operate correctly. Future versions may add additional restrictions to ensure kubelets have the minimal set of permissions required to operate correctly.
### OwnerReferencesPermissionEnforcement {#ownerreferencespermissionenforcement} ### OwnerReferencesPermissionEnforcement {#ownerreferencespermissionenforcement}