Merge pull request #1170 from ankon/pr/admin-masters

Set /O=system:masters for the admin certificate DN
pull/1177/head
Matt Rickard 2017-02-23 11:19:11 -08:00 committed by GitHub
commit 54b692c0b0
2 changed files with 3 additions and 2 deletions

View File

@ -209,7 +209,7 @@ To change the `MaxPods` setting to 5 on the Kubelet, pass this flag: `--extra-co
This feature also supports nested structs. To change the `LeaderElection.LeaderElect` setting to `true` on the scheduler, pass this flag: `--extra-config=scheduler.LeaderElection.LeaderElect=true`.
To set the `AuthorizationMode` on the `apiserver` to `RBAC`, you can use: `--extra-config=apiserver.GenericServerRunOptions.AuthorizationMode=RBAC`. You should use `--extra-config=apiserver.GenericServerRunOptions.AuthorizationRBAC,SuperUser=minikube` as well in that case.
To set the `AuthorizationMode` on the `apiserver` to `RBAC`, you can use: `--extra-config=apiserver.GenericServerRunOptions.AuthorizationMode=RBAC`.
To enable all alpha feature gates, you can use: `--feature-gates=AllAlpha=true`

View File

@ -89,7 +89,8 @@ func GenerateSignedCert(certPath, keyPath string, ips []net.IP, alternateDNS []s
template := x509.Certificate{
SerialNumber: big.NewInt(2),
Subject: pkix.Name{
CommonName: "minikube",
CommonName: "minikube",
Organization: []string{"system:masters"},
},
NotBefore: time.Now(),
NotAfter: time.Now().Add(time.Hour * 24 * 365),