On 2021-09-23 07:44, Fabian Arrotin wrote:
On 23/09/2021 02:55, Neal Gompa wrote:
On Wed, Sep 22, 2021 at 7:12 PM Kevin Fenzi <kevin@xxxxxxxxx> wrote:
* Should we now delete the kubeadmin user? In 3.x I know they advise
to
do that after auth is setup.
I'm not sure that's a good idea. I'm not even certain that was a good
idea in the OCP 3.x days, because eliminating the kubeadmin user means
you lose your failsafe login if all else fails.
+1 here : the reason why we decided to still keep kubeadmin on the
other
OCP clusters used for CentOS CI and Stream is exactly for that reason :
still be able to login, if there is a problem with the oauth setup, and
troubleshoot issues if (for example) ipsilon or IPA have troubles ...
:-)
You can still use the kubeconfig from the installer (if you kept it) to
login with system:admin in case everything else fail.
_______________________________________________
infrastructure mailing list -- infrastructure@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to infrastructure-leave@xxxxxxxxxxxxxxxxxxxxxxx
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/infrastructure@xxxxxxxxxxxxxxxxxxxxxxx
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure