Deprecate system:nodes binding

This commit is contained in:
Jordan Liggitt
2017-08-01 12:00:19 -04:00
parent 9979f1d821
commit e475da8481
+2 -1
View File
@@ -461,12 +461,13 @@ The permissions required by individual control loops are contained in the <a hre
</tr> </tr>
<tr> <tr>
<td><b>system:node</b></td> <td><b>system:node</b></td>
<td><b>system:nodes</b> group (deprecated in 1.7)</td> <td><b>system:nodes</b> group (deprecated in 1.7, removed in 1.8)</td>
<td>Allows access to resources required by the kubelet component, <b>including read access to all secrets, and write access to all pods</b>. <td>Allows access to resources required by the kubelet component, <b>including read access to all secrets, and write access to all pods</b>.
As of 1.7, use of the [Node authorizer](/docs/admin/authorization/node/) As of 1.7, use of the [Node authorizer](/docs/admin/authorization/node/)
and [NodeRestriction admission plugin](/docs/admin/admission-controllers#NodeRestriction) and [NodeRestriction admission plugin](/docs/admin/admission-controllers#NodeRestriction)
is recommended instead of this role, and allow granting API access to kubelets based on the pods scheduled to run on them. is recommended instead of this role, and allow granting API access to kubelets based on the pods scheduled to run on them.
As of 1.7, when the `Node` authorization mode is enabled, the automatic binding to the `system:nodes` group is not created. As of 1.7, when the `Node` authorization mode is enabled, the automatic binding to the `system:nodes` group is not created.
As of 1.8, the automatic binding to the `system:nodes` group is not created.
</td> </td>
</tr> </tr>
<tr> <tr>