3 ms·
I didn't word my statement well. Yes, you can enable unauthenticated requests and you can grant the anonymous role access to the api. I didn't recall `--anonymo
by uberduper 3y ago
I didn't word my statement well.
Yes, you can enable unauthenticated requests and you can grant the anonymous role access to the api. I didn't recall `--anonymous-auth` to be true by default.
- peddling-brink 3y agoIt is on certain clouds. But that isn't overtly dangerous until someone binds system:anonymous to cluster admin.
- raesene9 3y agoMost of the major cloud distros (AKS being the notable exception) do have --anonymous-auth enabled, although it's generally just /version and a couple of other endpoints exposed. Makes it easy to find out what clusters are running what versions of k8s which is interesting, but not a major security issue.