-
Bug
-
Resolution: Unresolved
-
Major
-
None
-
4.21
-
None
Description of problem:
MicroShift's apiserver explicitly allow anonymous auth. Even if anonymous users do not have any RBAC permissions, and can therefore do nothing, this is considered to be a security flaw. Anonymous auth is used for readiness checks when starting MicroShift, but kubeconfigs already exist by then, so it could use authenticated queries to the health endpoint.
Version-Release number of selected component (if applicable):
4.21
How reproducible:
100%
Steps to Reproduce:
1. 2. 3.
Actual results:
Expected results:
Additional info: