Securizing API Server Roles on Openshift Container Platform 3.11
Issue
APIs are key to automating container management at scale. APIs are used to validate and configure the data for pods, services, and replication controllers; perform project validation on incoming requests; and invoke triggers on other major system components. API access control (authentication and authorization) is critical for securing your container platform. OpenShift allows anonymous requests to the API server to support information discovery and webhook integrations. Anonymous requests are assigned the system:unauthenticated group, which is bound to the following cluster-scoped roles by default:
Environment
- Openshift Container Platform 3.11 [RHCOP]
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.