Google Distributed Cloud 会将 Pod 部署到具有提升 RBAC 权限(例如修改所有 Deployment 和读取所有集群 Secret 的权限)的节点。Google Distributed Cloud 需要这些权限才能正常运行。
下表列出了具有提升权限的所有 Google Distributed Cloud 组件:
aisanet-operatoranthos-cluster-operatoranthos-multinet-controllercap-controller-managercapi-controller-managercapi-kubeadm-bootstrap-controller-managercdi-operatorcert-manager-cainjectorcert-manager-webhookcert-managercluster-metrics-webhookcsi-snapshot-controlleristio-ingressistiodkube-state-metricslocalpvmetallb-controllermetrics-server-operatormetrics-servernetwork-controller-managersp-anthos-static-provisionerstackdriver-operatorvirt-apivirt-controllervirt-handlervirt-operatorvm-controller-controller-managervmruntime-controller-manager