問題文
The kubelet on each node exposes an HTTPS endpoint. By default, requests to that endpoint that are not rejected by another configured authentication method are treated as anonymous, and the default authorization mode allows all requests. Which pair of settings closes that gap?
選択肢
- Turn off anonymous authentication on the kubelet and delegate authorization decisions to the API server through the webhook mode.
- Configure a client certificate authority on the kubelet and leave the authorization mode at its default value, so the node accepts only the callers it recognizes.
- Set the kubelet's authorization mode to AlwaysDeny and rely on the API server to bypass it, so the node itself never has to decide anything about the caller.
- Move the kubelet endpoint behind the cluster's Ingress controller and every request to the node passes through a proxy the platform team already operates.