4 ms·
One note of caution for those skimming the release notes: v1.5.0 now allows anonymous access to the API server by default. With the default k8s authorization b
by boyd 10y ago
One note of caution for those skimming the release notes: v1.5.0 now allows anonymous access to the API server by default. With the default k8s authorization being `AllowAll` this makes it very important to pass `--allow-anonymous=false` if updating from v1.4.x to v1.5.0.
It looks like this is going to be set to false for v1.5.1: https://github.com/kubernetes/kubernetes/pull/38708 https://github.com/kubernetes/kubernetes/pull/38708
- TheIronYuppie 10y agoThis is correct, and has been fixed. If you use kube-up or Google Container Engine, the default is set to false. Disclosure: I work at Google on Kubernetes.