The SDN pod is now running the kube-proxy code (at least for the time being), so it should have the node-proxier role. This was previously not an issue, because other roles grant similar permissions to the node-proxier role, but if people add permissions to the node-proxier role (e.g. idling), they need to also apply to the SDN pod's SA.
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|
||
|