I'm setting up a kubernetes clusters via "the hard way" but I"m stuck.
Right now I'm using flannel (tried canal too) and the apiserver runs with a 'kubernetes' cert.
I think what's happening is that the 'kubernetes' user doesn't have the proper permissions but I can't figure out actually how to configure it as the documentation seems sparse/complicated on this issue.
I've definitely RTFMd but can't figure this out.
Feb 08 19:24:34 host-d9c9d5e1.instances.us-west-1.scalefastr.cloud kubelet[10257]: I0208 19:24:34.381382 10257 server.go:248] Forbidden (user=kubernetes, verb=get, resource=nodes, subresource=proxy)
Feb 08 19:24:34 host-d9c9d5e1.instances.us-west-1.scalefastr.cloud kubelet[10257]: I0208 19:24:34.381576 10257 server.go:796] GET /containerLogs/default/busybox-855686df5d-ln6ww/busybox: (5.610932ms) 403
Feb 08 19:24:34 host-d9c9d5e1.instances.us-west-1.scalefastr.cloud kubelet[10257]: goroutine 963 [running]:
Feb 08 19:24:34 host-d9c9d5e1.instances.us-west-1.scalefastr.cloud kubelet[10257]: net/http.HandlerFunc.ServeHTTP(0xc4201a2240, 0x5769940, 0xc42025ea10, 0xc421036500)
Feb 08 19:24:34 host-d9c9d5e1.instances.us-west-1.scalefastr.cloud kubelet[10257]: /usr/local/go/src/net/http/server.go:1918 +0x44
Feb 08 19:24:34 host-d9c9d5e1.instances.us-west-1.scalefastr.cloud kubelet[10257]: net/http.(*ServeMux).ServeHTTP(0xc42075c9c0, 0x5769940, 0xc42025ea10, 0xc421036500)
Feb 08 19:24:34 host-d9c9d5e1.instances.us-west-1.scalefastr.cloud kubelet[10257]: /usr/local/go/src/net/http/server.go:2254 +0x130
Feb 08 19:24:34 host-d9c9d5e1.instances.us-west-1.scalefastr.cloud kubelet[10257]: net/http.serverHandler.ServeHTTP(0xc420a092b0, 0x576a580, 0xc421797c00, 0xc421036500)
Feb 08 19:24:34 host-d9c9d5e1.instances.us-west-1.scalefastr.cloud kubelet[10257]: /usr/local/go/src/net/http/server.go:2619 +0xb4
Feb 08 19:24:34 host-d9c9d5e1.instances.us-west-1.scalefastr.cloud kubelet[10257]: net/http.(*conn).serve(0xc4203e03c0, 0x576ca00, 0xc42183ff00)
Feb 08 19:24:34 host-d9c9d5e1.instances.us-west-1.scalefastr.cloud kubelet[10257]: /usr/local/go/src/net/http/server.go:1801 +0x71d
Feb 08 19:24:34 host-d9c9d5e1.instances.us-west-1.scalefastr.cloud kubelet[10257]: created by net/http.(*Server).Serve
Feb 08 19:24:34 host-d9c9d5e1.instances.us-west-1.scalefastr.cloud kubelet[10257]: /usr/local/go/src/net/http/server.go:2720 +0x288
Feb 08 19:24:34 host-d9c9d5e1.instances.us-west-1.scalefastr.cloud kubelet[10257]: logging error output: "Forbidden (user=kubernetes, verb=get, resource=nodes, subresource=proxy)"
Feb 08 19:24:34 host-d9c9d5e1.instances.us-west-1.scalefastr.cloud kubelet[10257]: [[Go-http-client/1.1]
195.201.30.240:58019]