Enable k8s RBAC everywhere via system level

Change-Id: Ic3ecace186b756f84c8d824cdb154845647c7dfd
diff --git a/classes/cluster/k8s-aio-calico/kubernetes/control.yml b/classes/cluster/k8s-aio-calico/kubernetes/control.yml
index cd49cca..98bc75b 100644
--- a/classes/cluster/k8s-aio-calico/kubernetes/control.yml
+++ b/classes/cluster/k8s-aio-calico/kubernetes/control.yml
@@ -5,6 +5,7 @@
 - system.salt.minion.cert.etcd_server_single
 - system.salt.minion.cert.k8s_server_single
 - system.kubernetes.master.single
+- system.kubernetes.master.auth.rbac
 - system.kubernetes.control.roles.cluster-admin
 - cluster.k8s-aio-calico.kubernetes.compute
 - cluster.k8s-aio-calico
diff --git a/classes/cluster/k8s-aio-contrail/kubernetes/control.yml b/classes/cluster/k8s-aio-contrail/kubernetes/control.yml
index c108c6e..acf2d8c 100644
--- a/classes/cluster/k8s-aio-contrail/kubernetes/control.yml
+++ b/classes/cluster/k8s-aio-contrail/kubernetes/control.yml
@@ -5,6 +5,7 @@
 - system.linux.system.repo.docker_legacy
 - system.salt.minion.cert.etcd_server
 - system.kubernetes.master.cluster
+- system.kubernetes.master.auth.rbac
 - system.kubernetes.control.roles.cluster-admin
 - cluster.k8s-aio-contrail.kubernetes
 - cluster.k8s-aio-contrail.kubernetes.compute
diff --git a/classes/cluster/k8s-compact/kubernetes/control.yml b/classes/cluster/k8s-compact/kubernetes/control.yml
index c0cc065..53dcbf8 100644
--- a/classes/cluster/k8s-compact/kubernetes/control.yml
+++ b/classes/cluster/k8s-compact/kubernetes/control.yml
@@ -4,6 +4,7 @@
 - service.etcd.server.single
 - service.kubernetes.control.cluster
 - system.kubernetes.master.single
+- system.kubernetes.master.auth.rbac
 - system.kubernetes.control.roles.cluster-admin
 - cluster.k8s-compact.kubernetes.compute
 parameters:
diff --git a/classes/cluster/k8s-ha-calico-cloudprovider/kubernetes/control.yml b/classes/cluster/k8s-ha-calico-cloudprovider/kubernetes/control.yml
index b2cdbaf..958cdd8 100644
--- a/classes/cluster/k8s-ha-calico-cloudprovider/kubernetes/control.yml
+++ b/classes/cluster/k8s-ha-calico-cloudprovider/kubernetes/control.yml
@@ -6,6 +6,7 @@
 - system.linux.system.repo.docker_legacy
 - system.salt.minion.cert.etcd_server
 - system.kubernetes.master.cluster
+- system.kubernetes.master.auth.rbac
 - system.kubernetes.control.roles.cluster-admin
 - cluster.k8s-ha-calico-cloudprovider.kubernetes.compute
 - cluster.k8s-ha-calico-cloudprovider
diff --git a/classes/cluster/k8s-ha-calico-flannel-virtlet/kubernetes/control.yml b/classes/cluster/k8s-ha-calico-flannel-virtlet/kubernetes/control.yml
index 34cace7..d6e794e 100644
--- a/classes/cluster/k8s-ha-calico-flannel-virtlet/kubernetes/control.yml
+++ b/classes/cluster/k8s-ha-calico-flannel-virtlet/kubernetes/control.yml
@@ -6,6 +6,7 @@
 - system.linux.system.repo.docker_legacy
 - system.salt.minion.cert.etcd_server
 - system.kubernetes.master.cluster
+- system.kubernetes.master.auth.rbac
 - system.kubernetes.control.roles.cluster-admin
 - cluster.k8s-ha-calico-flannel-virtlet.kubernetes.compute
 - cluster.k8s-ha-calico-flannel-virtlet
@@ -78,5 +79,3 @@
       namespace:
         netchecker:
           enabled: true
-      auth:
-        mode: Node,RBAC
diff --git a/classes/cluster/k8s-ha-calico-syndic/kubernetes/control.yml b/classes/cluster/k8s-ha-calico-syndic/kubernetes/control.yml
index 03a945e..bd70fbe 100644
--- a/classes/cluster/k8s-ha-calico-syndic/kubernetes/control.yml
+++ b/classes/cluster/k8s-ha-calico-syndic/kubernetes/control.yml
@@ -6,6 +6,7 @@
 - system.linux.system.repo.docker_legacy
 - system.salt.minion.cert.etcd_server
 - system.kubernetes.master.cluster
+- system.kubernetes.master.auth.rbac
 - system.kubernetes.control.roles.cluster-admin
 - cluster.k8s-ha-calico-syndic.kubernetes.compute
 - cluster.k8s-ha-calico-syndic
diff --git a/classes/cluster/k8s-ha-calico/kubernetes/control.yml b/classes/cluster/k8s-ha-calico/kubernetes/control.yml
index afde0e5..9c854ff 100644
--- a/classes/cluster/k8s-ha-calico/kubernetes/control.yml
+++ b/classes/cluster/k8s-ha-calico/kubernetes/control.yml
@@ -6,6 +6,7 @@
 - system.linux.system.repo.docker_legacy
 - system.salt.minion.cert.etcd_server
 - system.kubernetes.master.cluster
+- system.kubernetes.master.auth.rbac
 - system.kubernetes.control.roles.cluster-admin
 - cluster.k8s-ha-calico.kubernetes.compute
 - cluster.k8s-ha-calico
@@ -71,5 +72,3 @@
       namespace:
         netchecker:
           enabled: true
-      auth:
-        mode: Node,RBAC
diff --git a/classes/cluster/k8s-ha-contrail-40/kubernetes/control.yml b/classes/cluster/k8s-ha-contrail-40/kubernetes/control.yml
index 45f9465..fc5ed2f 100644
--- a/classes/cluster/k8s-ha-contrail-40/kubernetes/control.yml
+++ b/classes/cluster/k8s-ha-contrail-40/kubernetes/control.yml
@@ -9,6 +9,7 @@
 - system.salt.minion.cert.etcd_client
 - system.salt.minion.cert.etcd_server
 - system.kubernetes.master.cluster
+- system.kubernetes.master.auth.rbac
 - system.kubernetes.control.roles.cluster-admin
 - cluster.k8s-ha-contrail-40.infra
 - cluster.overrides
diff --git a/classes/cluster/k8s-ha-contrail/kubernetes/control.yml b/classes/cluster/k8s-ha-contrail/kubernetes/control.yml
index b2807ee..7c2d531 100644
--- a/classes/cluster/k8s-ha-contrail/kubernetes/control.yml
+++ b/classes/cluster/k8s-ha-contrail/kubernetes/control.yml
@@ -6,6 +6,7 @@
 - system.linux.system.repo.docker_legacy
 - system.salt.minion.cert.etcd_server
 - system.kubernetes.master.cluster
+- system.kubernetes.master.auth.rbac
 - system.kubernetes.control.roles.cluster-admin
 - cluster.k8s-ha-contrail.kubernetes.compute
 - cluster.k8s-ha-contrail
diff --git a/classes/cluster/sl-k8s-calico/kubernetes/control.yml b/classes/cluster/sl-k8s-calico/kubernetes/control.yml
index 270555a..b3e2038 100644
--- a/classes/cluster/sl-k8s-calico/kubernetes/control.yml
+++ b/classes/cluster/sl-k8s-calico/kubernetes/control.yml
@@ -5,6 +5,7 @@
 - system.linux.system.repo.mcp.apt_mirantis.docker_legacy
 - system.salt.minion.cert.etcd_server
 - system.kubernetes.master.cluster
+- system.kubernetes.master.auth.rbac
 - system.kubernetes.control.roles.cluster-admin
 - system.kubernetes.control.roles.fluentd-view
 - cluster.sl-k8s-calico.kubernetes.compute
@@ -58,5 +59,3 @@
       namespace:
         netchecker:
           enabled: ${_param:kubernetes_netchecker_enabled}
-      auth:
-        mode: Node,RBAC
diff --git a/classes/cluster/sl-k8s-contrail/kubernetes/control.yml b/classes/cluster/sl-k8s-contrail/kubernetes/control.yml
index 5176dc6..6c1b492 100644
--- a/classes/cluster/sl-k8s-contrail/kubernetes/control.yml
+++ b/classes/cluster/sl-k8s-contrail/kubernetes/control.yml
@@ -5,6 +5,7 @@
 - system.linux.system.repo.docker_legacy
 - system.salt.minion.cert.etcd_server
 - system.kubernetes.master.cluster
+- system.kubernetes.master.auth.rbac
 - system.kubernetes.control.roles.cluster-admin
 - system.kubernetes.control.roles.fluentd-view
 - cluster.sl-k8s-contrail.kubernetes.compute
diff --git a/classes/cluster/virtual-mcp11-k8s-calico-dyn/kubernetes/control.yml b/classes/cluster/virtual-mcp11-k8s-calico-dyn/kubernetes/control.yml
index 94958ec..08bac4e 100644
--- a/classes/cluster/virtual-mcp11-k8s-calico-dyn/kubernetes/control.yml
+++ b/classes/cluster/virtual-mcp11-k8s-calico-dyn/kubernetes/control.yml
@@ -6,6 +6,7 @@
 - system.linux.system.repo.docker_legacy
 - system.salt.minion.cert.etcd_server
 - system.kubernetes.master.cluster
+- system.kubernetes.master.auth.rbac
 - system.kubernetes.control.roles.cluster-admin
 - system.kubernetes.control.roles.fluentd-view
 - cluster.virtual-mcp11-k8s-calico-dyn.kubernetes.compute
diff --git a/classes/cluster/virtual-mcp11-k8s-calico-minimal/kubernetes/control.yml b/classes/cluster/virtual-mcp11-k8s-calico-minimal/kubernetes/control.yml
index 9c21917..077036e 100644
--- a/classes/cluster/virtual-mcp11-k8s-calico-minimal/kubernetes/control.yml
+++ b/classes/cluster/virtual-mcp11-k8s-calico-minimal/kubernetes/control.yml
@@ -6,6 +6,7 @@
 - system.linux.system.repo.docker_legacy
 - system.salt.minion.cert.etcd_server
 - system.kubernetes.master.cluster
+- system.kubernetes.master.auth.rbac
 - system.kubernetes.control.roles.cluster-admin
 - cluster.virtual-mcp11-k8s-calico-minimal.kubernetes.compute
 - cluster.virtual-mcp11-k8s-calico-minimal
diff --git a/classes/cluster/virtual-mcp11-k8s-calico/kubernetes/control.yml b/classes/cluster/virtual-mcp11-k8s-calico/kubernetes/control.yml
index 21a2573..ddfae1e 100644
--- a/classes/cluster/virtual-mcp11-k8s-calico/kubernetes/control.yml
+++ b/classes/cluster/virtual-mcp11-k8s-calico/kubernetes/control.yml
@@ -6,6 +6,7 @@
 - system.linux.system.repo.mcp.apt_mirantis.docker_legacy
 - system.salt.minion.cert.etcd_server
 - system.kubernetes.master.cluster
+- system.kubernetes.master.auth.rbac
 - system.kubernetes.control.roles.cluster-admin
 - system.kubernetes.control.roles.fluentd-view
 - cluster.virtual-mcp11-k8s-calico.kubernetes.compute
@@ -74,5 +75,3 @@
       namespace:
         netchecker:
           enabled: ${_param:kubernetes_netchecker_enabled}
-      auth:
-        mode: Node,RBAC
diff --git a/classes/cluster/virtual-mcp11-k8s-contrail/kubernetes/control.yml b/classes/cluster/virtual-mcp11-k8s-contrail/kubernetes/control.yml
index 1027e55..6cf8c91 100644
--- a/classes/cluster/virtual-mcp11-k8s-contrail/kubernetes/control.yml
+++ b/classes/cluster/virtual-mcp11-k8s-contrail/kubernetes/control.yml
@@ -6,6 +6,7 @@
 - system.linux.system.repo.docker_legacy
 - system.salt.minion.cert.etcd_server
 - system.kubernetes.master.cluster
+- system.kubernetes.master.auth.rbac
 - system.kubernetes.control.roles.cluster-admin
 - system.kubernetes.control.roles.fluentd-view
 - cluster.virtual-mcp11-k8s-contrail.kubernetes.compute