Dev Locks Kubernetes Core Components Out of Cluster by Enabling RBAC Too Early
A developer rebuilding a home lab Kubernetes cluster ran into a critical self-inflicted outage after enabling RBAC authorization on an empty MicroK8s cluster before core components were fully operational. The controller-manager and scheduler were immediately denied access to essential resources, including leader-election leases and scheduling objects, causing no pods or ReplicaSets to ever be created. Despite correct ClusterRoleBindings, certificates, and roles all being in place, the RBAC authorizer was not loading policy at all, leaving every rule present but unread. The cluster's health endpoint falsely reported everything as healthy because admin certificates bypass authorization entirely, masking the underlying failure. Disabling RBAC and restarting the cluster resolved the forbidden errors and restored lease acquisition, though some downstream issues persisted.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in