![]() Generates the new token on AWS, GCE, Vagrant. Renames instance metadata from "kube-token" to "kubelet-token". (Is this okay for GKE?) Having separate tokens for kubelet and kube-proxy permits using principle of least privilege, makes it easy to rate limit the clients separately, allows annotation of apiserver logs with the client identity at a finer grain than just source-ip. |
||
---|---|---|
.. | ||
templates | ||
config-default.sh | ||
config-test.sh | ||
options.md | ||
util.sh |