Document node authorization mode
This commit is contained in:
@@ -461,11 +461,12 @@ The permissions required by individual control loops are contained in the <a hre
|
||||
</tr>
|
||||
<tr>
|
||||
<td><b>system:node</b></td>
|
||||
<td><b>system:nodes</b> group</td>
|
||||
<td>Allows access to resources required by the kubelet component, <b>including read access to secrets, and write access to pods</b>.
|
||||
In the future, read access to secrets and write access to pods will be restricted to objects scheduled to the node.
|
||||
To maintain permissions in the future, Kubelets must identify themselves with the group <b>system:nodes</b> and a username in the form <b>system:node:<node-name></b>.
|
||||
See <a href="https://pr.k8s.io/40476">https://pr.k8s.io/40476</a> for details.
|
||||
<td><b>system:nodes</b> group (deprecated in 1.7)</td>
|
||||
<td>Allows access to resources required by the kubelet component, <b>including read access to all secrets, and write access to all pods</b>.
|
||||
As of 1.7, use of the [Node authorizer](/docs/admin/authorization/node/)
|
||||
and [NodeRestriction admission plugin](/docs/admin/admission-controllers#NodeRestriction)
|
||||
is recommended instead of this role, and allow granting API access to kubelets based on the pods scheduled to run on them.
|
||||
As of 1.7, when the `Node` authorization mode is enabled, the automatic binding to the `system:nodes` group is not created.
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
|
||||
Reference in New Issue
Block a user