Open
Description
What would you like to be added:
Today, there's at least one place in clusterloader2 (xref) in which we create role bindings to system:anonymous
.
Can we alter clusterloader2 to stop doing this?
Why is this needed:
Two reasons:
- Creating bindings to
system:anonymous
is generally a bad practice, even if in this particular case the role being bound only allows read permissions. - Some k8s distros reject such actions by default, thus making it harder to utilize clusterloader2.