Merge pull request #4572 from liggitt/node-role

Deprecate system:nodes binding
This commit is contained in:
Andrew Chen
2017-08-03 13:53:07 -07:00
committed by GitHub
+2 -1
View File
@@ -461,12 +461,13 @@ The permissions required by individual control loops are contained in the <a hre
</tr> </tr>
<tr> <tr>
<td><b>system:node</b></td> <td><b>system:node</b></td>
<td><b>system:nodes</b> group (deprecated in 1.7)</td> <td><b>system:nodes</b> group (deprecated in 1.7, removed in 1.8)</td>
<td>Allows access to resources required by the kubelet component, <b>including read access to all secrets, and write access to all pods</b>. <td>Allows access to resources required by the kubelet component, <b>including read access to all secrets, and write access to all pods</b>.
As of 1.7, use of the [Node authorizer](/docs/admin/authorization/node/) As of 1.7, use of the [Node authorizer](/docs/admin/authorization/node/)
and [NodeRestriction admission plugin](/docs/admin/admission-controllers#NodeRestriction) and [NodeRestriction admission plugin](/docs/admin/admission-controllers#NodeRestriction)
is recommended instead of this role, and allow granting API access to kubelets based on the pods scheduled to run on them. is recommended instead of this role, and allow granting API access to kubelets based on the pods scheduled to run on them.
As of 1.7, when the `Node` authorization mode is enabled, the automatic binding to the `system:nodes` group is not created. As of 1.7, when the `Node` authorization mode is enabled, the automatic binding to the `system:nodes` group is not created.
As of 1.8, the automatic binding to the `system:nodes` group is not created.
</td> </td>
</tr> </tr>
<tr> <tr>