If I get to the bottom of this #rabbithole and I don't find our very own #footguns I shall be very disappointed.
Because that means I shall have to talk to the #vendor and that seldom turns out well.
Maybe the behavior is documented. Technically. Piecewise in several different places, one of which is in a locked file cabinet in a planning office that is only open for one hour at lunch on alternate Thursdays.
@thelonelyghost A certain major cloud vendor's #Kubernetes implementation, and what happens when one must deal with both the "old" and "new" authn/authz schemes simultaneously in a cluster. It prefers new, but for best results, configure both for identical results, or at least as close as practical.
It wasn't our own smoking #footguns at the bottom of the #rabbithole, but at least there was a #deterministic answer that didn't require #vendor contact.