This message was deleted.
# general
a
This message was deleted.
c
Because the apiserver generally does not run as a pod in the cluster?
Or when it does it usually runs with host network, so you need to allow the node IP
n
@creamy-pencil-82913 I'm not sure I understand the nuance of what you're saying. the
kube-apiserver
entity does not specifically refer to a pod, or being inside the cluster. It just says
The kube-apiserver entity represents the kube-apiserver in a Kubernetes cluster. This entity represents both deployments of the kube-apiserver: within the cluster and outside of the cluster.
c
I suspect that using the kube-apiserver entity as the source in the policy was found to not work properly in some environments, otherwise we would have suggested that instead. I’m not sure though. Feel free to open an issue, I can see if someone on the team responsible for that component can comment.
n
Hi @creamy-pencil-82913, I opened an issue to clarify the matter and would be grateful if someone could take a look at it. Thanks, your help is much appreciated. https://github.com/rancher/rancher/issues/46051
Hi @creamy-pencil-82913 I'm still looking into this. Would it still be possible to get someone on the team to comment?