Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Stop creating role bindings for system:anonymous #3090

Open
acurtiz opened this issue Jan 10, 2025 · 0 comments
Open

Stop creating role bindings for system:anonymous #3090

acurtiz opened this issue Jan 10, 2025 · 0 comments
Labels
kind/feature Categorizes issue or PR as related to a new feature.

Comments

@acurtiz
Copy link

acurtiz commented Jan 10, 2025

What would you like to be added:

Today, there's at least one place in clusterloader2 (xref) in which we create role bindings to system:anonymous.

Can we alter clusterloader2 to stop doing this?

Why is this needed:

Two reasons:

  1. Creating bindings to system:anonymous is generally a bad practice, even if in this particular case the role being bound only allows read permissions.
  2. Some k8s distros reject such actions by default, thus making it harder to utilize clusterloader2.
@acurtiz acurtiz added the kind/feature Categorizes issue or PR as related to a new feature. label Jan 10, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/feature Categorizes issue or PR as related to a new feature.
Projects
None yet
Development

No branches or pull requests

1 participant