系统组件的 RBAC 权限

Anthos clusters on Bare Metal 会将 Pod 部署到具有提升 RBAC 权限(例如修改所有 Deployment 和读取所有集群 Secret 的权限)的节点。Anthos clusters on Bare Metal 需要这些权限才能正常运行。

下表列出了具有提升权限的所有 Anthos clusters on Bare Metal 组件:

  • ais
  • anet-operator
  • anthos-cluster-operator
  • anthos-multinet-controller
  • cap-controller-manager
  • capi-controller-manager
  • capi-kubeadm-bootstrap-controller-manager
  • cdi-operator
  • cert-manager-cainjector
  • cert-manager-webhook
  • cert-manager
  • cluster-metrics-webhook
  • csi-snapshot-controller
  • istio-ingress
  • istiod
  • kube-state-metrics
  • localpv
  • metallb-controller
  • metrics-server-operator
  • metrics-server
  • network-controller-manager
  • sp-anthos-static-provisioner
  • stackdriver-operator
  • virt-api
  • virt-controller
  • virt-handler
  • virt-operator
  • vm-controller-controller-manager
  • vmruntime-controller-manager