You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法关联Google服务账号与Kubernetes服务账号的问题排查

GCP Workload Identity配置权限问题排查

问题描述

我正按照GCP官方指南在GCP上配置带Workload Identity的Kubernetes集群,但在服务账号权限配置上遇到阻碍。

执行的操作步骤

gcloud container clusters create test-cluster \
    --region=europe-west1 \
    --workload-pool=my-project.svc.id.goog

gcloud container clusters get-credentials test-cluster \
    --region=europe-west1

kubectl create namespace test-kns

kubectl create serviceaccount test-ksa \
    --namespace test-kns

gcloud iam service-accounts create test-gsa \
    --project=my-project

gcloud projects add-iam-policy-binding my-project \
    --member "serviceAccount:test-gsa@my-project.iam.gserviceaccount.com" \
    --role "roles/composer.worker"

gcloud iam service-accounts add-iam-policy-binding test-gsa@my-project.iam.gserviceaccount.com \
    --role roles/iam.workloadIdentityUser \
    --member "serviceAccount:my-project.svc.id.goog[test-kns/test-ksa]"

kubectl annotate serviceaccount test-ksa \
    --namespace test-kns \
    iam.gke.io/gcp-service-account=test-gsa@my-project.iam.gserviceaccount.com

# 测试KSA权限,返回no
kubectl auth can-i list pods --all-namespaces --as "system:serviceaccount:test-kns:test-ksa"
# 输出:[no]

# 模拟GSA后测试,返回yes
gcloud config set auth/impersonate_service_account test-gsa@my-project.iam.gserviceaccount.com
gcloud container clusters get-credentials test-cluster --location europe-west1
kubectl auth can-i list pods --all-namespaces
# 输出:[yes]

已验证的配置

  • 服务账号注释已正确配置:
kubectl describe serviceaccount -n test-kns test-ksa                                        
Name:                test-ksa
Namespace:           test-kns
Labels:              <none>
Annotations:         iam.gke.io/gcp-service-account: test-gsa@my-project.iam.gserviceaccount.com
Image pull secrets:  <none>
Mountable secrets:   <none>
Tokens:              <none>
Events:              <none>
  • Pod中能正确获取GSA邮箱:
root@workload-identity-test:/# curl -H "Metadata-Flavor: Google" http://169.254.169.254/computeMetadata/v1/instance/service-accounts/default/email
test-gsa@my-project.iam.gserviceaccount.com

疑问

GSA与KSA之间是否缺少了什么配置?


解决方案

核心问题在于:kubectl auth can-i测试的是Kubernetes RBAC权限,而非GCP IAM权限。你已完成Workload Identity的身份映射(KSA可关联GSA获取GCP权限),但未给KSA配置对应的Kubernetes RBAC规则,使其拥有list pods --all-namespaces的权限。

权限体系区分

  • 模拟GSA执行测试时,使用的是GSA绑定的GCP IAM角色(如roles/container.admin这类可操作K8s集群的角色),因此返回yes。
  • 通过--as指定KSA测试时,验证的是该KSA在K8s集群内部的RBAC权限,由于未配置任何ClusterRole或RoleBinding,因此返回no。

具体修复步骤

若需让该KSA拥有集群级别的Pod查看权限,执行以下命令:

# 创建允许查看所有命名空间Pod的ClusterRole
kubectl create clusterrole pod-reader --verb=list --resource=pods
# 将ClusterRole绑定到test-kns命名空间下的test-ksa
kubectl create clusterrolebinding test-ksa-pod-reader --clusterrole=pod-reader --serviceaccount=test-kns:test-ksa

执行完成后再次测试:

kubectl auth can-i list pods --all-namespaces --as "system:serviceaccount:test-kns:test-ksa"

此时会返回yes。

补充说明

Workload Identity仅负责让K8s Pod通过KSA获取GCP IAM权限(如访问GCS、BigQuery等GCP服务),而K8s内部的资源访问权限仍需通过Kubernetes RBAC单独配置,二者是独立的权限体系。


内容的提问来源于stack exchange,提问作者jimbofreedman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 00:22:47