Re: Openshift 4 SOP PR review

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 




On 2021-09-23 07:44, Fabian Arrotin wrote:
On 23/09/2021 02:55, Neal Gompa wrote:
On Wed, Sep 22, 2021 at 7:12 PM Kevin Fenzi <kevin@xxxxxxxxx> wrote:

* Should we now delete the kubeadmin user? In 3.x I know they advise to
do that after auth is setup.


I'm not sure that's a good idea. I'm not even certain that was a good
idea in the OCP 3.x days, because eliminating the kubeadmin user means
you lose your failsafe login if all else fails.

+1 here : the reason why we decided to still keep kubeadmin on the other
OCP clusters used for CentOS CI and Stream is exactly for that reason :
still be able to login, if there is a problem with the oauth setup, and
troubleshoot issues if (for example) ipsilon or IPA have troubles ... :-)


You can still use the kubeconfig from the installer (if you kept it) to login with system:admin in case everything else fail.
_______________________________________________
infrastructure mailing list -- infrastructure@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to infrastructure-leave@xxxxxxxxxxxxxxxxxxxxxxx
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/infrastructure@xxxxxxxxxxxxxxxxxxxxxxx
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure




[Index of Archives]     [Fedora Development]     [Fedora Users]     [Fedora Desktop]     [Fedora SELinux]     [Yosemite News]     [KDE Users]

  Powered by Linux