From 56f9af866816f449368ee83d6a228f27537edc3d Mon Sep 17 00:00:00 2001 From: Cristian Calin Date: Wed, 31 Aug 2022 10:12:23 +0300 Subject: [PATCH] disable kubelet_authorization_mode_webhook by default --- roles/kubespray-defaults/defaults/main.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/roles/kubespray-defaults/defaults/main.yaml b/roles/kubespray-defaults/defaults/main.yaml index 22bf39fac..aca7e8ee5 100644 --- a/roles/kubespray-defaults/defaults/main.yaml +++ b/roles/kubespray-defaults/defaults/main.yaml @@ -444,7 +444,7 @@ rbac_enabled: "{{ 'RBAC' in authorization_modes }}" kubelet_authentication_token_webhook: true # When enabled, access to the kubelet API requires authorization by delegation to the API server -kubelet_authorization_mode_webhook: true +kubelet_authorization_mode_webhook: false # kubelet uses certificates for authenticating to the Kubernetes API # Automatically generate a new key and request a new certificate from the Kubernetes API as the current certificate approaches expiration