diff --git a/roles/kubernetes/master/templates/kubeadm-config.yaml.j2 b/roles/kubernetes/master/templates/kubeadm-config.yaml.j2
index e25804e66fb73879373fada9735d9527845c429a..e489bb115ab229f04fce5a69f04c2b2da3f86f35 100644
--- a/roles/kubernetes/master/templates/kubeadm-config.yaml.j2
+++ b/roles/kubernetes/master/templates/kubeadm-config.yaml.j2
@@ -56,10 +56,6 @@ apiServerExtraArgs:
   allow-privileged: "true"
 {% if kube_version | version_compare('1.9', '>=') %}
   requestheader-client-ca-file: "{{ kube_cert_dir }}/ca.pem"
-  requestheader-allowed-names: "{{ kube_api_requestheader_allowed_names }}"
-  requestheader-extra-headers-prefix: "X-Remote-Extra-"
-  requestheader-group-headers: "X-Remote-Group"
-  requestheader-username-headers: "X-Remote-User"
   enable-aggregator-routing: "{{ kube_api_aggregator_routing }}"
   proxy-client-cert-file: "{{ kube_cert_dir }}/front-proxy-client.pem"
   proxy-client-key-file: "{{ kube_cert_dir }}/front-proxy-client-key.pem"
diff --git a/roles/kubernetes/master/templates/manifests/kube-apiserver.manifest.j2 b/roles/kubernetes/master/templates/manifests/kube-apiserver.manifest.j2
index d6f065ea5c0bcff518a8149573dfcba4298e2455..f499e1a7d32698c91f063f7e0d2f8900371d5f02 100644
--- a/roles/kubernetes/master/templates/manifests/kube-apiserver.manifest.j2
+++ b/roles/kubernetes/master/templates/manifests/kube-apiserver.manifest.j2
@@ -102,7 +102,7 @@ spec:
 {% endif %}
 {% if kube_version | version_compare('1.9', '>=') %}
     - --requestheader-client-ca-file={{ kube_cert_dir }}/ca.pem
-    - --requestheader-allowed-names={{ kube_api_requestheader_allowed_names }}
+    - --requestheader-allowed-names=front-proxy-client
     - --requestheader-extra-headers-prefix=X-Remote-Extra-
     - --requestheader-group-headers=X-Remote-Group
     - --requestheader-username-headers=X-Remote-User
diff --git a/roles/kubespray-defaults/defaults/main.yaml b/roles/kubespray-defaults/defaults/main.yaml
index efec7bd3dc59c64cc12d0210296c6f9f2263f038..a76bfcc9f993edef3a2e37209fe00ce10fd5da64 100644
--- a/roles/kubespray-defaults/defaults/main.yaml
+++ b/roles/kubespray-defaults/defaults/main.yaml
@@ -122,8 +122,7 @@ kube_apiserver_port: 6443
 kube_apiserver_insecure_bind_address: 127.0.0.1
 kube_apiserver_insecure_port: 8080
 
-# Metrics server
-kube_api_requestheader_allowed_names: "front-proxy-client"
+# Aggregator
 kube_api_aggregator_routing: true
 
 # Path used to store Docker data