-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add service account to kube-dns addon #1970
Conversation
Can one of the admins verify this patch? |
@minikube-bot ok to test |
Codecov Report
@@ Coverage Diff @@
## master #1970 +/- ##
======================================
Coverage 30% 30%
======================================
Files 77 77
Lines 4740 4740
======================================
Hits 1422 1422
Misses 3138 3138
Partials 180 180 Continue to review full report at Codecov.
|
From https://storage.googleapis.com/minikube-builds/logs/1970/Linux-VirtualBox.txt.
Anywhere I could find more logs? |
Reproduced locally, this will not pass until #1904 go in, as there is no rolebinding for kube-dns service account. Though I'm surprised #1904 didn't fail the DNS test.
|
@MrHohn that PR adds the kube-system cluster role binding programmatically As far as localkube goes, there are probably a few other things we need to do until we can get RBAC working properly. Most likely the way forward is to deprecate localkube (for many reasons), and eventually default to our kubeadm-backed bootstrapping RBAC is enabled and dns is configured properly if you use |
@r2d4 I get the following error with
|
@vadimeisenbergibm the kubeadm bootstrapper will be released soon in v0.22.2 #1971 |
Issues go stale after 90d of inactivity. Prevent issues from auto-closing with an If this issue is safe to close now please do so with Send feedback to sig-testing, kubernetes/test-infra and/or |
Stale issues rot after 30d of inactivity. If this issue is safe to close now please do so with Send feedback to sig-testing, kubernetes/test-infra and/or fejta. |
Rotten issues close after 30d of inactivity. Send feedback to sig-testing, kubernetes/test-infra and/or fejta. |
From kubernetes/kubernetes#52487.
kube-dns will not be funcitoning without service account when RBAC is enabled.
And seems like we are setting authorization mode to RBAC by default: ref #1904.
cc @vadimeisenbergibm