Skip to content

Commit 1343b4a

Browse files
committed
eks/hollow-nodes: comment RBAC
Signed-off-by: Gyuho Lee <leegyuho@amazon.com>
1 parent 95352ed commit 1343b4a

File tree

1 file changed

+5
-6
lines changed

1 file changed

+5
-6
lines changed

eks/hollow-nodes/remote/remote.go

Lines changed: 5 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -306,6 +306,10 @@ func (ts *tester) deleteServiceAccount() error {
306306
return ts.cfg.EKSConfig.Sync()
307307
}
308308

309+
// need RBAC, otherwise
310+
// kubelet_node_status.go:92] Unable to register node "fake-node-000000-8pkvl" with API server: nodes "fake-node-000000-8pkvl" is forbidden: node "ip-192-168-83-61.us-west-2.compute.internal" is not allowed to modify node "fake-node-000000-8pkvl"
311+
// ref. https://github.com/kubernetes/kubernetes/issues/47695
312+
// ref. https://kubernetes.io/docs/reference/access-authn-authz/node
309313
// ref. https://github.com/kubernetes/client-go/tree/master/examples/in-cluster-client-configuration
310314
// ref. https://kubernetes.io/docs/reference/access-authn-authz/rbac/
311315
func (ts *tester) createALBRBACClusterRole() error {
@@ -542,12 +546,7 @@ func (ts *tester) deleteConfigMap() error {
542546
return ts.cfg.EKSConfig.Sync()
543547
}
544548

545-
// TODO: use "ReplicationController"?
546-
// TODO: not working for now
547-
// kubelet_node_status.go:92] Unable to register node "fake-node-000000-8pkvl" with API server: nodes "fake-node-000000-8pkvl" is forbidden: node "ip-192-168-83-61.us-west-2.compute.internal" is not allowed to modify node "fake-node-000000-8pkvl"
548-
// need remove "NodeRestriction" from "kube-apiserver --enable-admission-plugins"
549-
// ref. https://github.com/kubernetes/kubernetes/issues/47695
550-
// ref. https://kubernetes.io/docs/reference/access-authn-authz/node
549+
// TODO: use "ReplicationController" to max out
551550

552551
func (ts *tester) createDeployment() error {
553552
ngType := "custom"

0 commit comments

Comments
 (0)