如何通过Spring Boot+Kotlin程序化获取EKS服务并生成OAuth Token
程序化生成Amazon EKS OAuth Token(Spring Boot + Kotlin)
方案一:使用fabric8官方AWS认证适配(推荐)
fabric8 Kubernetes Client提供了专门的AWS EKS认证模块,无需手动生成token,自动从环境中获取AWS凭证完成认证。
- 添加依赖
在build.gradle.kts中添加fabric8的AWS认证依赖(版本需与你的kubernetes-client保持一致):
dependencies { implementation("io.fabric8:kubernetes-client-aws:6.7.2") }
- 修改Kubernetes Client配置
直接使用AwsAuthConfig自动适配EKS认证:
@Configuration class AwsConfig { @Bean fun kubernetesClient(): KubernetesClient { return KubernetesClientBuilder() .withConfig(AwsAuthConfig.loadAwsAuthConfig()) .build() } }
- 该配置会自动读取AWS环境凭证(EC2实例角色、EKS Pod IAM角色、本地AWS配置文件等),自动获取EKS集群信息并生成有效token。
- 需确保你的IAM实体(用户/角色)拥有
eks:DescribeCluster和sts:GetCallerIdentity权限。
方案二:手动程序化生成Token
如果需要手动控制token生成逻辑,可以通过AWS SDK for Java实现aws eks get-token的底层逻辑:
- 添加依赖
dependencies { implementation("software.amazon.awssdk:sts:2.20.0") implementation("software.amazon.awssdk:eks:2.20.0") implementation("io.jsonwebtoken:jjwt-api:0.11.5") runtimeOnly("io.jsonwebtoken:jjwt-impl:0.11.5") runtimeOnly("io.jsonwebtoken:jjwt-jackson:0.11.5") }
- 实现Token生成工具类
import software.amazon.awssdk.auth.credentials.DefaultCredentialsProvider import software.amazon.awssdk.regions.Region import software.amazon.awssdk.services.eks.EksClient import software.amazon.awssdk.services.eks.model.DescribeClusterRequest import software.amazon.awssdk.services.sts.StsClient import software.amazon.awssdk.services.sts.model.GetCallerIdentityRequest import io.jsonwebtoken.Jwts import io.jsonwebtoken.SignatureAlgorithm import java.util.* class EksTokenGenerator(private val clusterName: String, private val region: Region) { private val stsClient = StsClient.builder() .credentialsProvider(DefaultCredentialsProvider.create()) .region(region) .build() fun generateToken(): String { val callerIdentity = stsClient.getCallerIdentity(GetCallerIdentityRequest.builder().build()) val credentials = stsClient.credentialsProvider().resolveCredentials() // 构造符合EKS要求的JWT格式token val expiration = Date(System.currentTimeMillis() + 3600 * 1000) // 1小时有效期 return Jwts.builder() .setHeaderParam("alg", "RS256") .setHeaderParam("kid", "${region.id}/${credentials.accessKeyId()}") .claim("iss", "https://sts.amazonaws.com/${stsClient.serviceConfiguration().serviceEndpoint()}") .claim("sub", callerIdentity.userId()) .claim("aud", clusterName) .setExpiration(expiration) .signWith(credentials.signingKey(), SignatureAlgorithm.RS256) .compact() } }
- 整合到配置中
@Configuration class AwsConfig { private val clusterName = "your-cluster-name" private val region = Region.US_EAST_1 // 替换为你的集群实际区域 @Bean fun eksTokenGenerator(): EksTokenGenerator { return EksTokenGenerator(clusterName, region) } @Bean fun kubernetesClient(tokenGenerator: EksTokenGenerator): KubernetesClient { // 自动获取EKS集群Master URL val eksClient = EksClient.builder().region(region).build() val clusterEndpoint = eksClient.describeCluster( DescribeClusterRequest.builder().name(clusterName).build() ).cluster().endpoint() return KubernetesClientBuilder() .withConfig( ConfigBuilder() .withMasterUrl(clusterEndpoint) .withOauthToken(tokenGenerator.generateToken()) .withTrustCerts() .build() ) .build() } }
注意事项
- 无论采用哪种方案,运行环境的AWS凭证必须拥有
eks:DescribeCluster和sts:GetCallerIdentity权限。 - 在EKS集群内部运行时,推荐使用IAM Roles for Service Accounts (IRSA),无需额外配置本地凭证。
内容的提问来源于stack exchange,提问作者lior-der
相关产品推荐
相关产品推荐

