🚨 [Action Required] Transition Away from gcr.io/kubebuilder/kube-rbac-proxy

51 views
Skip to first unread message

Camila Macedo

unread,
Nov 26, 2024, 4:55:13 AM11/26/24
to Operator Framework

Hi Everyone,


The gcr.io/kubebuilder/kube-rbac-proxy image, historically used to secure metrics endpoints, will become unavailable.

Sometime in early 2025, the GCR will go away. Projects relying on it must migrate to avoid disruptions and ensure metrics endpoint security.

Key Update

Why This Matters

  • If your project depends on this image, it may no longer work if you need to pull the image once it becomes unavailable.

  • Unprotected metrics endpoints may expose sensitive data, like system performance and app behaviour, creating security risks.

What You Need to Do

  1. If you want to continue with kube-rbac-proxy:

  2. If you want to switch to use WithAuthenticationAndAuthorization:

    • Option 1: Upgrade your project using the latest release version of the tools. By default secure metrics handling (similar to kube-rbac-proxy).

Additionally, there are options to improve production readiness, such as configuring certificates.
This approach also allows you to take advantage of other improvements, bug fixes, and embrace the advancements.

For more information and guidance, see the FAQ and discussion.

Thank you for your attention, 


CAMILA MACEDO

Principal Software Engineer 

RED HAT Operator framework

Red Hat UK

She / Her / Hers

IM: cmacedo

I respect your work-life balance. Therefore, you do not need to answer this email outside of your office hours.



Reply all
Reply to author
Forward
0 new messages