Skip to content

track the rename of the "system:masters" group #2322

@neolit123

Description

@neolit123

Kubernetes includes a stock "system:masters" group that have full access to cluster resources:
https://kubernetes.io/docs/reference/access-authn-authz/rbac/

kubeadm binds its administrator account to this group:
https://github.com/kubernetes/kubernetes/blob/e45b8bfe0f45c276537bb8e927b2ae5af8466590/cmd/kubeadm/app/constants/constants.go#L168

this ticket is created with the assumption that the group name will be changed at some point (based on the efforts by wg-naming), potentially by introducing a new group that has the same level of access and deprecating the old group.

on the side of kubeadm we'd have to track this effort and adapt kubeadm to handle the introduction of the new group.

k/k issue: (NONE exists yet?)
plan: TODO

Metadata

Metadata

Assignees

Labels

kind/deprecationCategorizes issue or PR as related to a feature/enhancement marked for deprecation.kind/featureCategorizes issue or PR as related to a new feature.lifecycle/frozenIndicates that an issue or PR should not be auto-closed due to staleness.priority/important-longtermImportant over the long term, but may not be staffed and/or may need multiple releases to complete.sig/authCategorizes an issue or PR as relevant to SIG Auth.wg/namingCategorizes an issue or PR as relevant to WG Naming.

Type

No type

Projects

Status

Closed / Done

Relationships

None yet

Development

No branches or pull requests

Issue actions