Google Distributed Cloud는 모든 배포를 수정하고 모든 클러스터 보안 비밀을 읽는 등 승격된 역할 기반 액세스 제어(RBAC) 권한이 있는 노드에 포드를 배포합니다. Google Distributed Cloud가 올바르게 작동하려면 이러한 권한이 필요합니다.
승격된 RBAC 권한이 있는 구성요소는 다음과 같습니다.
- gke-connect-agent
- ais
- coredns-autoscaler
- kube-proxy
- calico-node
- anet-operator
- 금속
- cluster-health-controller
- gmsa-webhook
- onprem-user-cluster-controller
- gke-usage-metering
- metrics-server