Google Distributed Cloud は、すべての Deployment の変更とすべてのクラスタ Secret の読み取りなど、ロールベース アクセス制御(RBAC)の権限が昇格されたノードに Pod をデプロイします。これらの権限は、Google Distributed Cloud が正常に機能するために必要です。
次のコンポーネントには、昇格した RBAC 権限があります。
- gke-connect-agent
- ais
- coredns-autoscaler
- kube-proxy
- calico-node
- anet-operator
- metal
- cluster-health-controller
- gmsa-webhook
- onprem-user-cluster-controller
- gke-usage-metering
- metrics-server