You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
#3214 addresses this for the piece of code you're mentioning (i.e. scraping Prometheus targets).
The only other piece of code I see that's creating role bindings for system:anonymous is inside a measurement that is collecting pprof profiles from etcd/kube-apiserver/KCM/KS:
What would you like to be added:
Today, there's at least one place in clusterloader2 (xref) in which we create role bindings to
system:anonymous
.Can we alter clusterloader2 to stop doing this?
Why is this needed:
Two reasons:
system:anonymous
is generally a bad practice, even if in this particular case the role being bound only allows read permissions.The text was updated successfully, but these errors were encountered: