Skip to content

Stop creating role bindings for system:anonymous #3090

Open
@acurtiz

Description

@acurtiz

What would you like to be added:

Today, there's at least one place in clusterloader2 (xref) in which we create role bindings to system:anonymous.

Can we alter clusterloader2 to stop doing this?

Why is this needed:

Two reasons:

  1. Creating bindings to system:anonymous is generally a bad practice, even if in this particular case the role being bound only allows read permissions.
  2. Some k8s distros reject such actions by default, thus making it harder to utilize clusterloader2.

Metadata

Metadata

Assignees

No one assigned

    Labels

    kind/featureCategorizes issue or PR as related to a new feature.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions