Match each Kubernetes API server flag to its security function.
Drag a concept onto its matching description — or click a concept then click the description.
Enables RBAC authorization
Comma-separated list of admission controllers to enable
Disables anonymous requests to the API server
Path to a CA file for verifying kubelet certificates
File containing PEM-encoded x509 RSA or ECDSA private or public keys for service account token signing
Why these pairings
Correct matches: --authorization-mode=RBAC enables RBAC; --anonymous-auth=false disables anonymous auth; --profiling=false disables profiling. Common confusions involve mixing authorization and authentication flags.