diff --git a/docs/admin/admission-controllers.md b/docs/admin/admission-controllers.md index 34c945655c..e5f9baf1e3 100644 --- a/docs/admin/admission-controllers.md +++ b/docs/admin/admission-controllers.md @@ -268,6 +268,11 @@ extensions group (`--runtime-config=extensions/v1beta1/podsecuritypolicy=true`). See also [Pod Security Policy documentation](/docs/concepts/policy/pod-security-policy/) for more information. +### NodeRestriction + +This plug-in limits the `Node` and `Pod` objects a kubelet can modify. In order to be limited by this admission plugin, kubelets must use credentials in the `system:nodes` group, with a username in the form `system:node:`. +Such kubelets will only be allowed to modify their own `Node` API object, and only modify `Pod` API objects that are bound to their node. + ## Is there a recommended set of plug-ins to use? Yes.