diff --git a/site/content/docs/reference/supported-clusters.md b/site/content/docs/reference/supported-clusters.md index e9838166d..1eff4385d 100644 --- a/site/content/docs/reference/supported-clusters.md +++ b/site/content/docs/reference/supported-clusters.md @@ -37,3 +37,6 @@ token credential request API strategy by default. To choose the strategy to use with the concierge, use the `--concierge-mode` flag with `pinniped get kubeconfig`. Possible values are `ImpersonationProxy` and `TokenCredentialRequestAPI`. + +Do not use the command line option `--anonymous-auth=false` in the `kube-apiserver` CLI for a cluster that does not use the impersonation proxy strategy. This is because the `kube-apiserver` blocks unauthenticated access to the TokenCredentialRequest API of the Concierge, which will prevent users from being able to authenticate. +This does not matter while using the impersonation proxy strategy, which will allow these TokenCredentialRequests requests anyway.