The kube-apiserver flag --kubelet-client-certificate accepts a client certificate (kube-apiserver-kubelet-client.crt) to connect to the kubelet. There is no need for this certificate to have "system:masters" as "O" in the Subject, instead it can be a less privileged group like kubeadm's "kubeadm:cluster-admins". |
||
---|---|---|
.. | ||
_index.md | ||
certificates.md | ||
cluster-large.md | ||
enforcing-pod-security-standards.md | ||
multiple-zones.md | ||
node-conformance.md |